First published: Wed Jul 29 1998(Updated: )
dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Linux | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1406 is considered a moderate severity vulnerability as it can cause a denial of service due to system crashes.
To mitigate CVE-1999-1406, it is recommended to upgrade to a newer version of Red Hat Linux that does not include the vulnerable dumpreg utility.
Local users of Red Hat Linux 5.1 are affected by CVE-1999-1406 due to the improper handling of /dev/mem.
CVE-1999-1406 is a local denial of service vulnerability caused by the inappropriate access to /dev/mem.
CVE-1999-1406 cannot be exploited remotely as it requires local access to the system.