PT-2000-1993 · Iputils+1 · Iputils+1
Published
2000-10-18
·
Updated
2016-10-18
·
CVE-2000-1213
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iputils versions prior to 20001010
Red Hat Linux versions 6.2 through 7
Description
The issue is related to the ping utility in iputils, which does not drop privileges after acquiring a raw socket. This increases the exposure of ping to bugs that would otherwise occur at lower privileges.
Recommendations
For iputils versions prior to 20001010, consider restricting the use of the ping utility until a patch is available.
For Red Hat Linux versions 6.2 through 7, update the iputils package to a version that includes the necessary privilege drop functionality.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Iputils