PT-2005-1033 · Debian · Shorewall

Supernaut

·

Published

2005-07-19

·

Updated

2008-09-05

·

CVE-2005-2317

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Shorewall versions 2.4.x through 2.4.0 Shorewall versions 2.2.x through 2.2.4 Shorewall versions 2.0.x through 2.0.16
Description The issue allows remote attackers with an accepted MAC address to bypass other firewall rules or policies when MACLIST TTL is greater than 0 or MACLIST DISPOSITION is set to ACCEPT. Multiple vulnerabilities in the Shorewall package of the Debian GNU/Linux operating system can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Shorewall versions 2.4.x through 2.4.0, update to version 2.4.1 or later. For Shorewall versions 2.2.x through 2.2.4, update to version 2.2.5 or later. For Shorewall versions 2.0.x through 2.0.16, update to version 2.0.17 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03161
CVE-2005-2317
DSA-849-1

Affected Products

Shorewall