SB1999123101 - Resource exhaustion in Linux kernel
Published: December 31, 1999
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-1999-1339)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.
Remediation
Install update from vendor's website.