Linux Kernel IPTables Logging Rules Integer下溢漏洞

漏洞信息详情

Linux Kernel IPTables Logging Rules Integer下溢漏洞

漏洞简介

用于Linux 2.6.8以前版本的iptables的防火墙日志规则存在整数下溢漏洞。远程攻击者可以借助畸形IP数据包导致服务拒绝(应用程序崩溃)。

漏洞公告

It is reported that this issue is already fixed in the 2.6.8 upstream Linux kernel.
SuSE has released an advisory (SUSE-SA:2004:037) and fixes to address this vulnerability in SuSE products. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes.
MandrakeSoft has issued fixes in advisory MDKSA-2005:022. See reference section.
TurboLinux has released Turbolinux Security Announcement 28/Feb/2005 dealing with this and other issues. Please see the referenced advisory for more information.

Linux kernel 2.6

Linux kernel 2.6.3

Linux kernel 2.6.4

参考网址

来源: XF
名称: linux-ip-packet-dos(17800)
链接:http://xforce.iss.net/xforce/xfdb/17800

来源: BID
名称: 11488
链接:http://www.securityfocus.com/bid/11488

来源: SUSE
名称: SUSE-SA:2004:037
链接:http://www.novell.com/linux/security/advisories/2004_37_kernel.html

来源: SECUNIA
名称: 11202
链接:http://secunia.com/advisories/11202/

来源: MANDRAKE
名称: MDKSA-2005:022
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:022

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享