SB1999102201 - Insufficient verification of data authenticity in Linux kernel
Published: October 22, 1999
Security Bulletin ID
SB1999102201
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-1999-1341)
The vulnerability allows a local user to read and manipulate data.
Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.
Remediation
Install update from vendor's website.