SB2001123101 - Improper input validation in Linux kernel
Published: December 31, 2001
Security Bulletin ID
SB2001123101
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2001-1572)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.
Remediation
Install update from vendor's website.