CVE-2000-0440: Medium severity NetBSD NetBSD vulnerability
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
At the network edge (firewall/ACL/WAF), drop or block incoming packets that contain IP timestamp options or otherwise malformed IP option fields to prevent triggering the unaligned IP timestamp handling path.
- Operational
Monitor systems for signs of the denial-of-service (kernel crashes, high CPU, network stack failures) and apply vendor-supplied patches or updates as soon as they are released; investigate any instances where malformed IP timestamp packets were observed.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0440?
CVE-2000-0440 is classified as a denial of service vulnerability affecting NetBSD and FreeBSD.
How does CVE-2000-0440 allow an attacker to exploit the system?
CVE-2000-0440 allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
Which versions of NetBSD are affected by CVE-2000-0440?
NetBSD versions 1.4.1 and 1.4.2 are affected by CVE-2000-0440.
Which versions of FreeBSD are impacted by CVE-2000-0440?
FreeBSD versions 3.4, 4.0, and 5.0 are impacted by CVE-2000-0440.
How can I mitigate the risks associated with CVE-2000-0440?
To mitigate CVE-2000-0440, it is recommended to upgrade to a patched version of NetBSD or FreeBSD that addresses this vulnerability.