SB1999102201 - Insufficient verification of data authenticity in Linux kernel 



SB1999102201 - Insufficient verification of data authenticity in Linux kernel

Published: October 22, 1999

Security Bulletin ID SB1999102201
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient verification of data authenticity (CVE-ID: CVE-1999-1341)

The vulnerability allows a local user to read and manipulate data.

Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.


Remediation

Install update from vendor's website.