CVE-1999-1066: Medium severity sgi quake 1 server vulnerability
Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Quake 1 Serverfrom your environment.If the server is not required, uninstall or disable the Quake 1 server to eliminate the amplification vector.
- Compensating control
Apply network-level mitigations to prevent abuse as an amplifier: implement ingress/egress filtering to block spoofed source IPs (e.g., unicast RPF/BCP38), restrict or firewall the server's UDP game port to trusted networks only, and/or rate-limit UDP responses at the network edge to reduce possible amplification.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1066?
CVE-1999-1066 is classified as a medium severity vulnerability due to its potential to facilitate amplification attacks.
How do I fix CVE-1999-1066?
To mitigate CVE-1999-1066, restrict access to the Quake 1 server and apply network-level filtering to prevent spoofed requests.
What type of attack does CVE-1999-1066 enable?
CVE-1999-1066 enables attackers to perform Smurf-style amplification attacks by exploiting the UDP response behavior of the Quake 1 server.
Which software is affected by CVE-1999-1066?
CVE-1999-1066 affects the SGI Quake 1 server.
Can CVE-1999-1066 be exploited remotely?
Yes, CVE-1999-1066 can be exploited remotely by attackers to amplify traffic against another host.