CVE-1999-0446: Low severity NetBSD NetBSD vulnerability

Published Apr 12, 1999
·
Updated

Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.

Affected Software

3 affected components
NetBSD NetBSD=1.3.1
NetBSD NetBSD=1.3.2
NetBSD NetBSD=1.3.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove or restrict execution of the ln binary for untrusted local users so they cannot create the specially-crafted symbolic link (for example, ensure ln is owned by root and not executable by unprivileged users).

    /bin/ln (NetBSD ln command) executable permission / access = restrict execution to trusted/administrative accounts
  2. Compensating control

    Limit local account privileges and access: disable or remove unneeded local accounts, restrict which users can log in interactively, and apply filesystem ACLs or local policy to prevent untrusted users from creating symbolic links.

  3. Operational

    Monitor NetBSD vendor/security advisories for a patch or fixed release addressing the VFS ln symlink DoS and apply the vendor-supplied fix when it becomes available.

Event History

Apr 12, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the vulnerability associated with CVE-1999-0446?

CVE-1999-0446 allows local users to perform a denial of service in NetBSD version 1.3.3 and earlier by creating an unusual symbolic link.

2

What are the affected versions listed under CVE-1999-0446?

The affected versions under CVE-1999-0446 include NetBSD 1.3.1, 1.3.2, and 1.3.3.

3

How can I mitigate the issue described in CVE-1999-0446?

Mitigation for CVE-1999-0446 involves upgrading to a version of NetBSD that is later than 1.3.3.

4

Is CVE-1999-0446 a remote or local vulnerability?

CVE-1999-0446 is classified as a local vulnerability, as it requires local user access to exploit.

5

What impact does CVE-1999-0446 have on system stability?

The impact of CVE-1999-0446 is a denial of service, which can cause instability in the affected NetBSD systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203