Input validation error - CVE-1999-0103

 

Input validation error - CVE-1999-0103

Published: February 8, 1996 / Updated: August 4, 2020


Vulnerability identifier: #VU33851
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-1999-0103
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.


Affected software

dbus (Alpine package)
krb5 (Alpine package)
perl-net-ssleay (Alpine package)

How to mitigate CVE-1999-0103

Install update from vendor's website.

krb5 (Alpine package) - update to 1.11.2-r2
perl-net-ssleay (Alpine package) - update to 1.55-r1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins