CVE-1999-0727: Medium severity OpenBSD OpenBSD vulnerability

Published Aug 6, 1999
·
Updated

A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

Affected Software

1 affected component
OpenBSD OpenBSD=2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable IPsec in the OpenBSD kernel or in system IPsec configuration to prevent IPsec packets from being sent unencrypted until a kernel fix is applied.

    OpenBSD kernel (IPsec) ipsec_enabled = false
  2. Compensating control

    Block or restrict IPsec-related traffic (ESP/AH or IPsec UDP encapsulation) at network perimeter devices or apply ACLs to limit IPsec tunnels to fully trusted hosts until a kernel fix is available.

  3. Operational

    Avoid transmitting sensitive data over IPsec tunnels and reconfigure services to use alternative, trusted secure transports until the OpenBSD kernel issue is remediated; monitor network traffic for signs of unencrypted IPsec packets.

Event History

Aug 6, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Mar 22, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0727?

CVE-1999-0727 is classified as a moderate severity vulnerability.

2

How do I fix CVE-1999-0727?

To fix CVE-1999-0727, upgrade to a secure version of OpenBSD that addresses this kernel leak.

3

What systems are impacted by CVE-1999-0727?

CVE-1999-0727 affects OpenBSD version 2.5, specifically concerning IPsec packet encryption.

4

What does CVE-1999-0727 exploit?

CVE-1999-0727 exploits a kernel leak in the OpenBSD kernel allowing IPsec packets to be sent unencrypted.

5

Is CVE-1999-0727 a remote vulnerability?

CVE-1999-0727 can potentially be exploited remotely due to its impact on network packet handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203