CVE-1999-0727: Medium severity OpenBSD OpenBSD vulnerability
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable IPsec in the OpenBSD kernel or in system IPsec configuration to prevent IPsec packets from being sent unencrypted until a kernel fix is applied.
OpenBSD kernel (IPsec) ipsec_enabled = false - Compensating control
Block or restrict IPsec-related traffic (ESP/AH or IPsec UDP encapsulation) at network perimeter devices or apply ACLs to limit IPsec tunnels to fully trusted hosts until a kernel fix is available.
- Operational
Avoid transmitting sensitive data over IPsec tunnels and reconfigure services to use alternative, trusted secure transports until the OpenBSD kernel issue is remediated; monitor network traffic for signs of unencrypted IPsec packets.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0727?
CVE-1999-0727 is classified as a moderate severity vulnerability.
How do I fix CVE-1999-0727?
To fix CVE-1999-0727, upgrade to a secure version of OpenBSD that addresses this kernel leak.
What systems are impacted by CVE-1999-0727?
CVE-1999-0727 affects OpenBSD version 2.5, specifically concerning IPsec packet encryption.
What does CVE-1999-0727 exploit?
CVE-1999-0727 exploits a kernel leak in the OpenBSD kernel allowing IPsec packets to be sent unencrypted.
Is CVE-1999-0727 a remote vulnerability?
CVE-1999-0727 can potentially be exploited remotely due to its impact on network packet handling.