Description
The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
Products
- Debian Debian Linux 2.1
- Linux Kernel 2.0.34
- Linux Kernel 2.0.35
- Linux Kernel 2.0.36
- Linux Kernel 2.0.37
- Linux Kernel 2.0.38
- Linux Kernel 2.0
- Red Hat Linux 5.2 on i386
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-1999-0986, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-1999-0986 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
- Check out the advisory links provided below.
References