CVE-1999-1314: Low severity FreeBSD FreeBSD vulnerability

Published May 17, 1996
·
Updated

Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mountunion commands.

Affected Software

6 affected components
FreeBSD FreeBSD=2.0.5
FreeBSD FreeBSD=2.2-current
FreeBSD FreeBSD=2.1.0
FreeBSD FreeBSD<=2.2
FreeBSD FreeBSD=2.1-stable
FreeBSD FreeBSD=2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove FreeBSD union file system from your environment.

    Uninstall or avoid loading the union file system component on affected systems if it is not needed.

  2. Configuration

    Disable union file system support if not required. Remove or do not load the unionfs kernel module or rebuild the kernel without unionfs to prevent mount_union operations.

    FreeBSD union file system unionfs_enabled = false
  3. Compensating control

    Prevent untrusted local users from invoking mount_union or related mount operations. Restrict execution to trusted administrators (for example, remove execute/setuid bits or enforce access via sudoers/ACLs) to limit exposure until a vendor fix is applied.

  4. Operational

    Monitor FreeBSD vendor advisories for patches addressing the union file system vulnerability and apply vendor-supplied fixes when they become available. Until patched, continue to monitor for unexpected system reloads or crashes that may indicate exploitation.

Event History

May 17, 1996
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1314?

CVE-1999-1314 is classified as a denial of service vulnerability that can affect the system's stability.

2

How do I fix CVE-1999-1314?

To mitigate CVE-1999-1314, upgrade to a version of FreeBSD that is newer than 2.2.

3

Who is affected by CVE-1999-1314?

Local users of FreeBSD versions 2.2 and earlier are affected by CVE-1999-1314.

4

What can an attacker do using CVE-1999-1314?

An attacker can execute a series of mount_union commands to cause a system reload, leading to a denial of service.

5

Is CVE-1999-1314 specific to FreeBSD?

Yes, CVE-1999-1314 specifically affects FreeBSD operating systems and potentially other Unix-like systems with similar vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203