Junglewise Threat Intelligence

CVE-1999-0217: Sun Microsystems SunOS denial of service via UDP packet options

CVE-1999-0217 · Severity: medium · CVSS 5 · Published 1997-01-01

Vendors: Sun Microsystems.

Executive brief

A vulnerability in the SunOS operating system allows a remote attacker to force a system to restart by sending specially crafted network traffic. This affects the availability of the server, potentially causing service disruptions and downtime for applications running on the host. Because the attack can be launched over the network without any user interaction, it poses a risk to the operational stability of legacy SunOS environments.

Technical details

A denial-of-service vulnerability exists in the networking stack of SunOS 4.1.3. The flaw is triggered by the processing of UDP packets containing malicious or malformed option settings. An unauthenticated remote attacker can exploit this by sending a crafted UDP packet to the target system, causing the kernel to crash and the system to reboot. This issue is categorized as a remote denial-of-service (DoS) attack that requires no prior authentication or local access.

Affected products

  • Sun Microsystems SunOS 4.1.3

Timeline

  • 1997-01-01: disclosed: NVD Published Date

References