SB2002030801 - Security features in Linux kernel



SB2002030801 - Security features in Linux kernel

Published: March 8, 2002

Security Bulletin ID SB2002030801
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features (CVE-ID: CVE-2002-0060)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions.


Remediation

Install update from vendor's website.