CVE-2000-0112: High severity Debian Debian Linux vulnerability
The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
floppy_drivefrom your environment.Physically remove or disable floppy drives on systems where floppy boot support is not required.
- Configuration
Configure the system BIOS and/or the Debian installer boot order to disable booting from floppy disks during installation to prevent local users from booting from floppy media.
BIOS/boot configuration (installer) boot_from_floppy = disabled - Compensating control
Restrict local physical access to machines during installation and ensure floppy disks/media are removed or secured so local users cannot boot from removable floppy media.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0112?
CVE-2000-0112 is considered a moderate severity vulnerability because it allows local users to exploit system boot processes.
How do I fix CVE-2000-0112?
To fix CVE-2000-0112, ensure that the Master Boot Record (MBR) is secured and configured to prevent booting from external media.
Who is affected by CVE-2000-0112?
CVE-2000-0112 affects installations of Debian GNU/Linux versions 2.0, 2.0-r5, 2.1, and 2.2.
What kind of attack can be performed using CVE-2000-0112?
An attacker can use CVE-2000-0112 to boot from a floppy disk, allowing them to run unauthorized code on the system.
Is CVE-2000-0112 still relevant today?
While CVE-2000-0112 was discovered over two decades ago, it is still relevant for legacy systems running affected versions of Debian.