PT-2000-1993 · Iputils+1 · Iputils+1
Publicado
2000-10-18
·
Atualizado
2016-10-18
·
CVE-2000-1213
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iputils versions prior to 20001010
Red Hat Linux versions 6.2 through 7
Description
The issue is related to the ping utility in iputils, which does not drop privileges after acquiring a raw socket. This increases the exposure of ping to bugs that would otherwise occur at lower privileges.
Recommendations
For iputils versions prior to 20001010, consider restricting the use of the ping utility until a patch is available.
For Red Hat Linux versions 6.2 through 7, update the iputils package to a version that includes the necessary privilege drop functionality.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Iputils