CVE-1999-0831: Medium severity Cobalt Qube vulnerability
Denial of service in Linux syslogd via a large number of connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict and rate-limit incoming connections to syslogd at the network perimeter (firewall, ACLs, or WAF). Limit allowed syslog source IPs to trusted hosts or isolate the syslog service on a management network to mitigate denial-of-service caused by a large number of connections.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0831?
CVE-1999-0831 is considered a denial of service vulnerability that can lead to significant service disruptions.
How can I mitigate CVE-1999-0831?
To mitigate CVE-1999-0831, implement firewall rules to limit incoming connections to syslogd.
Which systems are affected by CVE-1999-0831?
CVE-1999-0831 affects Cobalt Qube versions 1.0 and 2.0, Sun Cobalt RaQ versions 1.1, 2, and 3i, Debian GNU/Linux 2.2, and SUSE Linux versions 6.2 and 6.3.
What are the symptoms of CVE-1999-0831 exploitation?
Exploitation of CVE-1999-0831 may result in the syslogd service becoming unresponsive due to an overwhelming number of connections.
Is there a patch available for CVE-1999-0831?
There is no specific patch for CVE-1999-0831, but it is recommended to upgrade to an unaffected version of the software or to apply configuration changes to mitigate the risk.