SB1999072701 - Improper input validation in Linux kernel
Published: July 27, 1999 Updated: August 7, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-1999-1018)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
Remediation
Install update from vendor's website.