CVE-1999-0798: Buffer Overflow

Published Dec 4, 1998
·
Updated

Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

Affected Software

9 affected components
redhat Linux
SCO Internet FastStart
FreeBSD FreeBSD=6.2-stable
OpenBSD OpenBSD=2.4
SCO UnixWare=7.0
SCO OpenServer
BSDI Bsd Os
SCO UnixWare=7.0.1
OpenBSD OpenBSD=2.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove bootpd from your environment.

    Uninstall or remove the bootpd daemon from systems where BOOTP/DHCP services are not required (applicable to OpenBSD, FreeBSD, Linux, BSDI BSD/OS, Red Hat Linux, SCO products, and Xinuos UnixWare).

  2. Configuration

    Disable the bootpd service so it does not start automatically on affected systems (OpenBSD, FreeBSD, Linux, BSDI BSD/OS, Red Hat Linux, SCO Internet FastStart, SCO OpenServer, Xinuos UnixWare) if the service is not required.

    bootpd service_enabled = false
  3. Compensating control

    Apply network-level controls to block or restrict BOOTP/DHCP traffic (UDP ports 67 and 68) from untrusted networks; isolate systems running bootpd to trusted management networks and enforce ACLs or firewall rules to prevent external access.

  4. Operational

    Immediately stop/terminate any running bootpd instances on affected systems until a patch or vendor fix is available.

Event History

Dec 4, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0798?

CVE-1999-0798 has a high severity level due to its buffer overflow vulnerability that can allow remote exploitation.

2

How do I fix CVE-1999-0798?

To fix CVE-1999-0798, update your affected operating system to the latest patched version provided by your vendor.

3

What systems are impacted by CVE-1999-0798?

CVE-1999-0798 affects OpenBSD, FreeBSD, and various Linux distributions such as Red Hat and SCO systems.

4

What type of vulnerability is CVE-1999-0798?

CVE-1999-0798 is a buffer overflow vulnerability that occurs through malformed header types in bootpd.

5

Can CVE-1999-0798 be exploited remotely?

Yes, CVE-1999-0798 can be exploited remotely due to the nature of the buffer overflow in bootpd.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203