CVE-2002-1976: Low severity Linux Linux kernel vulnerability
ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKETMRPROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1976?
CVE-2002-1976 has a severity rating that varies depending on the affected system context but is generally considered a high risk due to the potential for undetected network snooping.
How do I fix CVE-2002-1976?
To fix CVE-2002-1976, update to a version of the Linux kernel that addresses this vulnerability and consider disabling promiscuous mode if not needed.
What systems are affected by CVE-2002-1976?
CVE-2002-1976 affects various versions of the Linux kernel, including 2.2.x and 2.4.x versions specified in its definitions.
What is the impact of CVE-2002-1976?
The impact of CVE-2002-1976 is the potential for unauthorized network traffic monitoring through undetected promiscuous mode operation.
Who can exploit CVE-2002-1976?
CVE-2002-1976 can be exploited by attackers with local access who can manipulate network settings to enable promiscuous mode without detection.