CVE-2000-0489: Low severity NetBSD NetBSD vulnerability

Published Sep 5, 1999
·
Updated

FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.

Affected Software

20 affected components
NetBSD NetBSD=1.4
FreeBSD FreeBSD=3.1
NetBSD NetBSD=1.4.2
NetBSD NetBSD=1.4.2
NetBSD NetBSD=1.4.2
NetBSD NetBSD=1.4.1
NetBSD NetBSD=1.4.2
NetBSD NetBSD=1.4.1
OpenBSD OpenBSD=2.7
FreeBSD FreeBSD=3.0
FreeBSD FreeBSD=3.2
FreeBSD FreeBSD=3.3
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=3.4
FreeBSD FreeBSD=3.5
FreeBSD FreeBSD=5.0-alpha
OpenBSD OpenBSD=2.6
NetBSD NetBSD=1.4.1
OpenBSD OpenBSD=2.5
NetBSD NetBSD=1.4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure kernel/sysctl or other supported system settings to restrict the maximum socket send/receive buffer sizes so setsockopt cannot allocate excessively large buffers.

    BSD kernel (socket buffer limits) maximum socket buffer size (SO_SNDBUF/SO_RCVBUF) = enforce an upper bound / reduce to a reasonable maximum
  2. Configuration

    Configure per-user and per-process resource limits (for example via shell limits or BSD resource limit mechanisms) to cap the number of sockets or file descriptors and prevent creation of a very large number of socket pairs.

    System resource limits per-user / per-process number of open sockets / file descriptors = set a reasonable cap
  3. Compensating control

    Isolate untrusted or exposed workloads (jails/containers/VMs) and restrict network exposure; implement monitoring and alerting for abnormal socket creation or high socket buffer allocations and block or throttle offending sources at the network edge.

  4. Operational

    Monitor systems for resource exhaustion due to excessive socketpair creation, terminate or throttle offending processes to reclaim resources, and apply vendor-supplied patches or fixes as soon as they become available.

Event History

Sep 5, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0489?

CVE-2000-0489 has been classified as a denial of service vulnerability affecting multiple BSD operating systems.

2

How do I fix CVE-2000-0489?

To fix CVE-2000-0489, you should update your FreeBSD, NetBSD, or OpenBSD systems to a version that addresses this vulnerability.

3

Which operating systems are affected by CVE-2000-0489?

CVE-2000-0489 affects FreeBSD, NetBSD, and OpenBSD, specifically older versions like FreeBSD 3.x and various NetBSD releases.

4

What is the impact of exploiting CVE-2000-0489?

Exploiting CVE-2000-0489 can lead to a denial of service condition, disrupting the availability of the affected system.

5

Is CVE-2000-0489 still a concern today?

While CVE-2000-0489 targets older operating systems, it remains a concern for systems that have not been updated or are still in use.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203