Vulnerability identifier: #VU100006
Vulnerability risk: Low
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-285
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
Mitigation
Install update from vendor's repository.
Vulnerable software versions
Linux kernel: All versions
External links
https://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000432
https://www.caldera.com/support/security/advisories/CSSA-2001-038.0.txt
https://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3
https://www.linuxsecurity.com/advisories/other_advisory-1683.html
https://www.novell.com/linux/security/advisories/2001_039_kernel2_txt.html
https://www.redhat.com/support/errata/RHSA-2001-142.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/7461
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.