PT-2005-1033 · Debian · Shorewall
Supernaut
·
Published
2005-07-19
·
Updated
2008-09-05
·
CVE-2005-2317
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shorewall versions 2.4.x through 2.4.0
Shorewall versions 2.2.x through 2.2.4
Shorewall versions 2.0.x through 2.0.16
Description
The issue allows remote attackers with an accepted MAC address to bypass other firewall rules or policies when MACLIST TTL is greater than 0 or MACLIST DISPOSITION is set to ACCEPT. Multiple vulnerabilities in the Shorewall package of the Debian GNU/Linux operating system can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations
For Shorewall versions 2.4.x through 2.4.0, update to version 2.4.1 or later.
For Shorewall versions 2.2.x through 2.2.4, update to version 2.2.5 or later.
For Shorewall versions 2.0.x through 2.0.16, update to version 2.0.17 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shorewall