Junglewise Threat Intelligence

CVE-1999-1314: FreeBSD union file system denial of service via mount_union

CVE-1999-1314 · Severity: low · CVSS 2.1 · Published 1996-05-17

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

A vulnerability in the FreeBSD operating system's union file system allows a local user to crash the system. By executing specific commands related to mounting file systems, an attacker can force the computer to reload or reboot. This results in a denial of service, interrupting operations and potentially causing unsaved data to be lost.

Technical details

A denial of service vulnerability exists in the union file system (unionfs) of FreeBSD 2.2 and earlier. The flaw is triggered when a local user executes a specific sequence of 'mount_union' commands, which leads to a kernel-level failure and subsequent system reload. This is a local attack requiring shell access to the target system. The vulnerability stems from improper handling of union mounts, a feature that allows multiple directories to appear as one. A patch was historically provided in FreeBSD security advisory SA-96:10.

Affected products

  • FreeBSD FreeBSD 2.2 and earlier

Timeline

  • 1996-05-17: advisory: Initial publication of the vulnerability details.

References