Improper input validation in Linux kernel - CVE-1999-0804

 

Improper input validation in Linux kernel - CVE-1999-0804

Published: June 1, 1999 / Updated: November 6, 2024


Vulnerability identifier: #VU99992
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-1999-0804
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.


Affected software

Linux kernel

How to mitigate CVE-1999-0804

Install update from vendor's repository.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins