Junglewise Threat Intelligence

CVE-1999-0796: FreeBSD T/TCP Extensions for Transactions spoofing vulnerability

CVE-1999-0796 · Severity: high · CVSS 7.5 · Published 1998-05-01

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

A vulnerability exists in the FreeBSD implementation of T/TCP (TCP Extensions for Transactions), a protocol designed to speed up network communications. An attacker can exploit this flaw to impersonate legitimate users or systems, potentially gaining unauthorized access to data or disrupting network services. This could lead to a loss of data integrity and unauthorized system access across the network.

Technical details

The FreeBSD implementation of T/TCP (TCP Extensions for Transactions) contains a vulnerability that allows for connection spoofing. T/TCP was designed to reduce the overhead of the standard TCP three-way handshake by using a connection count (CC) option to validate segments. However, flaws in the validation logic or the predictability of these transaction identifiers allow a remote, unauthenticated attacker to inject malicious traffic or hijack sessions. This bypasses the security assumptions of the transaction extensions, leading to potential unauthorized data access or service disruption. Users are generally advised to disable T/TCP extensions as the protocol has been largely deprecated due to these inherent security risks.

Affected products

  • FreeBSD FreeBSD T/TCP Extensions enabled versions

Timeline

  • 1998-05-01: disclosed: Initial publication date

References