Vulnerability Description
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.2.10 |
References
- http://marc.info/?l=bugtraq&m=93312523904591&w=2
- http://www.securityfocus.com/bid/543PatchVendor Advisory
- http://marc.info/?l=bugtraq&m=93312523904591&w=2
- http://www.securityfocus.com/bid/543PatchVendor Advisory
FAQ
What is CVE-1999-1018?
CVE-1999-1018 is a vulnerability with a CVSS score of 7.5 (HIGH). IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragmen...
How severe is CVE-1999-1018?
CVE-1999-1018 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1018?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.