CVE-1999-0305

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Feb 1, 1998
Updated: Nov 20, 2024

Summary

CVE-1999-0305 is a vulnerability affecting the system configuration control (sysctl) facility in older versions of OpenBSD (2.2 and earlier) and FreeBSD (2.2.5 and earlier). This issue enables remote attackers to spoof TCP connections by not properly restricting source-routed packets, even when the dosourceroute or forwarding variables are set to restrict them. This vulnerability poses a significant risk as it allows unauthorized access and manipulation of network traffic. Attackers can exploit this to conduct various malicious activities, including data theft, denial-of-service attacks, and man-in-the-middle attacks. System administrators are advised to update their operating systems to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • OpenBSD
  • FreeBSD

Affected Vendors

  • OpenBSD Project
  • FreeBSD Project