Junglewise Threat Intelligence

CVE-1999-1503: Network Flight Recorder nfrd denial of service via malformed TCP packet

CVE-1999-1503 · Severity: medium · CVSS 5 · Published 1998-04-08

Executive brief

Network Flight Recorder (NFR) is a network monitoring and intrusion detection system used to analyze traffic for security threats. A vulnerability in versions 1.5 and 1.6 allows a remote attacker to crash the monitoring service by sending a specially crafted network packet. This results in a denial of service, effectively blinding the security system and preventing it from detecting other malicious activity on the network.

Technical details

A denial of service vulnerability exists in the nfrd daemon of Network Flight Recorder (NFR) versions 1.5 and 1.6. The flaw is triggered when the engine processes a malformed TCP packet characterized by a null header and null data field. An unauthenticated remote attacker can exploit this by sending such a packet to the monitored network, causing the nfrd process to crash. This stops all network traffic recording and analysis. A patch was reportedly made available via SecurityFocus (BID 63) to address the issue.

Affected products

  • Network Flight Recorder Network Flight Recorder (NFR) 1.5, 1.6

Timeline

  • 1998-04-08: disclosed
  • 1998-04-08: advisory: NVD published date

References