CVE-2000-0041: Medium severity macOS vulnerability
Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If feasible, disable the generation of ICMP error responses or configure the host to rate-limit ICMP replies so the system does not emit large ICMP datagrams in response to malformed packets.
macOS ICMP error responses = disabled or rate-limited - Compensating control
At network perimeter devices (firewalls/routers) block or rate-limit ICMP traffic and filter malformed or oversized ICMP/fragmented packets. Implement ingress/egress filtering to reduce IP spoofing and limit the ability to use internal hosts as amplifiers.
- Operational
Monitor network and host telemetry for unusually large outbound ICMP responses; if detected, isolate impacted hosts, enable detailed logging, and notify network/security teams and upstream providers to mitigate ongoing amplification.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0041?
CVE-2000-0041 is considered a medium severity vulnerability due to its potential for amplification in flood attacks.
How do I fix CVE-2000-0041?
To mitigate CVE-2000-0041, it is recommended to apply security updates and patches provided by Apple for macOS.
What systems are affected by CVE-2000-0041?
CVE-2000-0041 affects Macintosh systems running macOS 9.0.
What type of attack does CVE-2000-0041 enable?
CVE-2000-0041 can be exploited to conduct flood attacks using large ICMP datagrams.
Is CVE-2000-0041 a remote or local vulnerability?
CVE-2000-0041 is a remote vulnerability that can be exploited over the network.