CVE-1999-1339: Medium severity FreeBSD FreeBSD vulnerability

Published Dec 31, 1999
·
Updated

Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.

Affected Software

2 affected components
FreeBSD FreeBSD=3.2
Linux Linux kernel<=2.2.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove ipchains (Linux) from your environment.

    Uninstall ipchains from systems where it is not required to eliminate the vulnerable NAT handling.

  2. Remove

    Remove ipfw (FreeBSD) from your environment.

    Uninstall ipfw from systems where it is not required to eliminate the vulnerable NAT handling.

  3. Configuration

    Disable NAT in ipchains (turn off ipchains NAT functionality) to prevent the ping -R (record route) input case that can cause a kernel panic.

    Linux (ipchains) NAT enabled = false
  4. Configuration

    Disable NAT in ipfw (turn off ipfw NAT functionality) to prevent the ping -R (record route) input case that can cause a kernel panic.

    FreeBSD (ipfw) NAT enabled = false
  5. Compensating control

    At the network perimeter or upstream routers/firewalls, block or filter ICMP echo requests that include the record-route option (ping -R) to prevent remote attackers from triggering the vulnerability.

Event History

Dec 31, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1339?

CVE-1999-1339 is considered a moderate severity vulnerability due to its potential to cause a denial of service.

2

How do I fix CVE-1999-1339?

To mitigate CVE-1999-1339, upgrade to Linux Kernel versions later than 2.2.10 or FreeBSD versions later than 3.2.

3

What systems are affected by CVE-1999-1339?

CVE-1999-1339 affects Linux Kernel versions up to 2.2.10 and FreeBSD 3.2.

4

What type of attack does CVE-1999-1339 facilitate?

CVE-1999-1339 facilitates a denial of service attack that can result in a kernel panic.

5

Is CVE-1999-1339 still a relevant vulnerability?

While it is an older vulnerability, CVE-1999-1339 remains relevant for systems still running affected versions of the software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203