SB2001073001 - Resource management errors in Linux kernel
Published: July 30, 2001
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management errors (CVE-ID: CVE-2001-1056)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a 'DCC SEND' request to a malicious server which listens on port 6667, which may cause the module to believe that the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.
Remediation
Install update from vendor's website.