CVE-1999-1518: Medium severity NetBSD NetBSD vulnerability

Published Jul 15, 1999
·
Updated

Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

Affected Software

20 affected components
NetBSD NetBSD=1.4
FreeBSD FreeBSD=3.1
FreeBSD FreeBSD=2.2.5
FreeBSD FreeBSD=2.2.2
NetBSD NetBSD=1.3.1
FreeBSD FreeBSD=2.2.3
FreeBSD FreeBSD=2.0.5
FreeBSD FreeBSD=1.1.5.1
NetBSD NetBSD=1.3.3
FreeBSD FreeBSD=2.2.8
FreeBSD FreeBSD=3.0
FreeBSD FreeBSD=3.2
FreeBSD FreeBSD=2.2.4
FreeBSD FreeBSD=2.1.0
FreeBSD FreeBSD=2.2.6
FreeBSD FreeBSD=2.1.6
FreeBSD FreeBSD=2.1.7.1
NetBSD NetBSD=1.3.2
FreeBSD FreeBSD=2.1.5
FreeBSD FreeBSD=2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Reduce per-process and per-user memory-related rlimits for untrusted or nonessential accounts (e.g., lower RLIMIT_AS/RLIMIT_DATA equivalents) to reduce the impact of excessive mmap/shmget allocations.

    Operating system process resource limits (rlimit) rlimit (memory) = lower limits for untrusted/local users as appropriate
  2. Compensating control

    Isolate untrusted or high-risk workloads and user accounts (for example via containers, jails, VMs or similar OS isolation) so that a single user-triggered mmap/shmget allocation cannot cause system-wide denial of service.

  3. Operational

    Implement monitoring and alerting for processes performing large or numerous mmap/shmget allocations or generating excessive page faults; automatically throttle, terminate, or investigate offending processes when thresholds are exceeded.

Event History

Jul 15, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1518?

CVE-1999-1518 is classified as a denial of service vulnerability that can be exploited by an unauthenticated user.

2

How do I fix CVE-1999-1518?

To remediate CVE-1999-1518, upgrade to a version of FreeBSD or NetBSD that is not affected by this vulnerability.

3

Which systems are affected by CVE-1999-1518?

CVE-1999-1518 affects multiple versions of FreeBSD and NetBSD, specifically versions 1.1.5.1 through 3.2 for FreeBSD and some versions of NetBSD.

4

What type of attack does CVE-1999-1518 enable?

CVE-1999-1518 enables a denial of service attack through memory allocation exploits using mmap or shmget.

5

Is there a workaround for CVE-1999-1518?

Currently, there are no specific workarounds for CVE-1999-1518 other than applying security patches or upgrades provided by the operating system vendor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203