PT-2016-6646 · Palo Alto Networks+7 · Pan-Os+7

Yue Cao

·

Published

2016-07-31

·

Updated

2021-11-17

·

CVE-2016-5696

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.7 PAN-OS versions 6.1, 7.0.15 and earlier, 7.1.9 and earlier
Description The issue is related to the improper determination of the rate of challenge ACK segments in the Linux kernel and PAN-OS, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack. This allows potential attackers to RST valid connections, as well as inject data on unencrypted connections. An off-path attacker may also be able to leak certain information about a given connection by creating congestion on the global challenge ACK rate limit counter and then measuring the changes by probing packets. Successful exploitation of this issue may allow an attacker to terminate a TCP connection or inject a payload into non-secured TCP connection between two endpoints on the network.
Recommendations For Linux kernel versions prior to 4.7, update to version 4.7 or later to resolve the issue. For PAN-OS versions 6.1, 7.0.15 and earlier, update to a version later than 7.0.15. For PAN-OS versions 7.1.9 and earlier, update to a version later than 7.1.9. As a temporary workaround, consider restricting access to sensitive data transmitted over TCP connections until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1853
ALT-PU-2017-1330
CESA-2016_1633
CESA-2016_1664
CVE-2016-5696
DLA-609-1
DSA-3659-1
MGASA-2016-0271
MGASA-2016-0283
OPENSUSE-SU-2016_2290-1
OPENSUSE-SU-2016_2625-1
OPENSUSE-SU-2016_3021-1
RHSA-2016:1631
RHSA-2016:1632
RHSA-2016:1633
RHSA-2016:1657
RHSA-2016:1664
RHSA-2016:1814
RHSA-2016:1815
RHSA-2016:1939
RHSA-2016_1632
RHSA-2016_1633
RHSA-2016_1664
SUSE-SU-2016:2245-1
SUSE-SU-2016:2912-1
SUSE-SU-2016:2976-1
SUSE-SU-2016:3069-1
SUSE-SU-2016:3304-1
SUSE-SU-2017:0437-1
SUSE-SU-2017:0471-1
SUSE-SU-2017:1102-1
USN-3070-1
USN-3070-2
USN-3070-3
USN-3070-4
USN-3071-1
USN-3071-2
USN-3072-1
USN-3072-2

Affected Products

Alt Linux
Centos
Fortios
Linux Kernel
Pan-Os
Red Hat
Suse
Ubuntu