SB2001123101 - Improper input validation in Linux kernel 



SB2001123101 - Improper input validation in Linux kernel

Published: December 31, 2001

Security Bulletin ID SB2001123101
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2001-1572)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.


Remediation

Install update from vendor's website.