SB2002030801 - Security features in Linux kernel
Published: March 8, 2002
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features (CVE-ID: CVE-2002-0060)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions.
Remediation
Install update from vendor's website.
References
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:041
- http://marc.info/?l=bugtraq&m=101483396412051&w=2
- http://marc.info/?l=vuln-dev&m=101486352429653&w=2
- http://www.kb.cert.org/vuls/id/230307
- http://www.netfilter.org/security/2002-02-25-irc-dcc-mask.html
- http://www.redhat.com/support/errata/RHSA-2002-028.html
- http://www.securityfocus.com/bid/4188
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0203-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8302