PT-2004-1718 · Linux+1 · Linux Kernel+2
Publicado
2004-07-06
·
Atualizado
2017-07-11
·
CVE-2004-0626
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 2.6
Description
The issue allows remote attackers to cause a denial of service, specifically CPU consumption by an infinite loop, when using iptables and TCP options rules. This occurs due to a large option length that produces a negative integer after a casting operation to the char type in the
tcp find option function of the netfilter subsystem.Recommendations
For Linux kernel version 2.6, consider applying configuration changes to restrict the use of TCP options rules with iptables to minimize the risk of exploitation. As a temporary workaround, restrict access to the netfilter subsystem until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Iptables
Netfilter