CVE-1999-0783: Medium severity freebsd freebsd vulnerability
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until a vendor fix is applied, reduce exposure by limiting local user privileges (avoid granting shell or write access to untrusted accounts), restrict NFS exports to trusted hosts only, and consider mounting NFS filesystems with restrictive options (for example, use nodev where appropriate) to reduce the impact of device special files.
- Operational
Monitor FreeBSD security advisories and vendor announcements for a kernel patch that addresses the hard-link-from-device-to-NFS denial-of-service issue, and apply the issued kernel update/patch as soon as it is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0783?
CVE-1999-0783 has a high severity rating due to its ability to cause a denial of service on affected FreeBSD systems.
How do I fix CVE-1999-0783?
To fix CVE-1999-0783, ensure that your FreeBSD system is upgraded to a version that is not affected by this vulnerability.
Who is affected by CVE-1999-0783?
Local users on FreeBSD 2.2 systems are primarily affected by CVE-1999-0783.
What type of attack does CVE-1999-0783 facilitate?
CVE-1999-0783 facilitates a denial of service attack by allowing users to create a hard link from a device file to an NFS file.
When was CVE-1999-0783 first reported?
CVE-1999-0783 was first reported in 1999 and is associated with vulnerabilities in FreeBSD version 2.2.