SB2002030801 - Security features in Linux kernel
Published: March 8, 2002
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Security features (CVE-ID: CVE-2002-0060)
CWE-ID: CWE-254 - Security Features
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions.
Remediation
Install update from vendor's website.
References
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:041
- http://marc.info/?l=bugtraq&m=101483396412051&w=2
- http://marc.info/?l=vuln-dev&m=101486352429653&w=2
- http://www.kb.cert.org/vuls/id/230307
- http://www.netfilter.org/security/2002-02-25-irc-dcc-mask.html
- http://www.redhat.com/support/errata/RHSA-2002-028.html
- http://www.securityfocus.com/bid/4188
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0203-027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8302