SB1999102201 - Insufficient verification of data authenticity in Linux kernel
Published: October 22, 1999
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-1999-1341)
The vulnerability allows a local user to read and manipulate data.
Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.
Remediation
Install update from vendor's website.