CVE-1999-1331: Low severity redhat Linux vulnerability
netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
netcfg 2.16-1from your environment.Uninstall netcfg 2.16-1 if the package is not required to prevent local users from being able to control the Ethernet interface on reboot.
- Configuration
In netcfg configuration, disable the option that allows users to control the Ethernet interface on reboot so that unprivileged users cannot shut down the interface during reboot.
netcfg option allowing Ethernet interface control on reboot = disabled - Compensating control
Restrict reboot and network-reconfiguration privileges to trusted administrators (for example, limit who can reboot the system or perform network interface changes) to mitigate the risk of local users causing a denial of service via this issue.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1331?
CVE-1999-1331 is considered a moderate severity vulnerability that allows local users to cause a denial of service.
How do I fix CVE-1999-1331?
To fix CVE-1999-1331, remove the option that allows users to control the Ethernet interface on reboot in the netcfg configuration.
Who is affected by CVE-1999-1331?
CVE-1999-1331 affects users running Red Hat Linux version 4.2 with specific netcfg options enabled.
What type of attack does CVE-1999-1331 enable?
CVE-1999-1331 enables local users to perform a denial of service by shutting down the Ethernet interface.
Can CVE-1999-1331 be exploited remotely?
CVE-1999-1331 cannot be exploited remotely; it requires local access to the system.