CVE-2000-0369: Medium severity Caldera OpenLinux vulnerability
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IDENT server in Caldera Linux 2.3from your environment.Uninstall the IDENT server component if it is not required.
- Configuration
Stop and disable the IDENT daemon/service to prevent remote attackers from causing a denial of service.
IDENT server in Caldera Linux 2.3 enabled = false - Compensating control
Restrict or block remote access to the IDENT service at the network perimeter (allow only trusted hosts) until the service is removed or a vendor fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0369?
CVE-2000-0369 has a moderate severity level as it can lead to a denial of service.
How do I fix CVE-2000-0369?
To fix CVE-2000-0369, consider upgrading to a patched version of Caldera Linux or disabling the IDENT server.
What software is affected by CVE-2000-0369?
CVE-2000-0369 affects Caldera OpenLinux version 2.3.
What type of attack does CVE-2000-0369 facilitate?
CVE-2000-0369 allows remote attackers to launch a denial of service attack.
Can CVE-2000-0369 be exploited remotely?
Yes, CVE-2000-0369 can be exploited remotely through the IDENT server.