CVE-1999-0764: Medium severity netbsd netbsd vulnerability

Published May 1, 1999
·
Updated

NetBSD allows ARP packets to overwrite static ARP entries.

Affected Software

1 affected component
NetBSD NetBSD=1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Enable network-level ARP protections to prevent unauthorized ARP updates from reaching NetBSD hosts. Examples: enable Dynamic ARP Inspection (DAI) or equivalent on switches, enable port security and DHCP snooping, and filter/validate ARP on upstream devices.

  2. Compensating control

    Restrict ARP traffic to trusted sources and isolate vulnerable hosts: place systems that rely on static ARP entries in separated VLANs or networks and apply firewall/ACL rules so only trusted management hosts can send ARP traffic to those systems.

  3. Operational

    Audit and monitor static ARP entries on NetBSD hosts: record current static ARP mappings, detect and alert on any unexpected overwrites, re-apply verified static entries when appropriate, and investigate incidents where static entries were overwritten.

Event History

May 1, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0764?

The severity of CVE-1999-0764 is classified as high due to its ability to overwrite static ARP entries.

2

How do I fix CVE-1999-0764?

To fix CVE-1999-0764, it is recommended to update to a version of NetBSD that does not allow ARP packets to overwrite static ARP entries.

3

Which versions of NetBSD are affected by CVE-1999-0764?

CVE-1999-0764 affects NetBSD version 1.3.

4

What type of vulnerability is CVE-1999-0764?

CVE-1999-0764 is a vulnerability related to the Address Resolution Protocol (ARP) allowing packet manipulation.

5

Can CVE-1999-0764 lead to network security issues?

Yes, CVE-1999-0764 can lead to serious network security issues such as ARP spoofing and man-in-the-middle attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203