Input validation error - CVE-1999-0103
Published: February 8, 1996 / Updated: August 4, 2020
Vulnerability identifier: #VU33851
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-1999-0103
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
Affected software
dbus (Alpine package)
krb5 (Alpine package)
perl-net-ssleay (Alpine package)
krb5 (Alpine package)
perl-net-ssleay (Alpine package)
How to mitigate CVE-1999-0103
Install update from vendor's website.
krb5 (Alpine package) - update to 1.11.2-r2
perl-net-ssleay (Alpine package) - update to 1.55-r1
perl-net-ssleay (Alpine package) - update to 1.55-r1