漏洞信息详情
Linux Kernel IPTables Logging Rules Integer下溢漏洞
- CNNVD编号:CNNVD-200412-115
- 危害等级: 中危
- CVE编号:
CVE-2004-0816
- 漏洞类型:
边界条件错误
- 发布时间:
2004-12-23
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
suse - 漏洞来源:
Discovery of this … -
漏洞简介
用于Linux 2.6.8以前版本的iptables的防火墙日志规则存在整数下溢漏洞。远程攻击者可以借助畸形IP数据包导致服务拒绝(应用程序崩溃)。
漏洞公告
It is reported that this issue is already fixed in the 2.6.8 upstream Linux kernel.
SuSE has released an advisory (SUSE-SA:2004:037) and fixes to address this vulnerability in SuSE products. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes.
MandrakeSoft has issued fixes in advisory MDKSA-2005:022. See reference section.
TurboLinux has released Turbolinux Security Announcement 28/Feb/2005 dealing with this and other issues. Please see the referenced advisory for more information.
Linux kernel 2.6
-
TurboLinux kernel-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-2.6.0-20.i586.rpm -
TurboLinux kernel-doc-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-doc-2.6.0-20.i586.rpm -
TurboLinux kernel-extramodules-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-extramodules-2.6.0-20.i586.rpm -
TurboLinux kernel-headers-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-headers-2.6.0-20.i586.rpm -
TurboLinux kernel-pcmcia-cs-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-pcmcia-cs-2.6.0-20.i586.rpm -
TurboLinux kernel-smp-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-smp-2.6.0-20.i586.rpm -
TurboLinux kernel-source-2.6.0-20.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u
pdates/RPMS/kernel-source-2.6.0-20.i586.rpm
Linux kernel 2.6.3
-
Mandrake kernel-2.6.3.25mdk-1-1mdk.amd64.rpmMandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-i686-up-4GB-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-i686-up-4GB-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-p3-smp-64GB-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-p3-smp-64GB-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.6.3.25mdk-1-1mdk.amd64.rpmMandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.6.3.25mdk-1-1mdk.amd64.rpmMandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.6.3.25mdk-1-1mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.6.3-25mdk.amd64.rpmMandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.6.3-25mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.6.3-25mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-stripped-2.6.3-25mdk.amd64.rpmMandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-stripped-2.6.3-25mdk.i586.rpmMandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-stripped-2.6.3-25mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Linux kernel 2.6.4
-
SuSE kernel-bigsmp-2.6.5-7.111.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6
.5-7.111.i586.rpm -
SuSE kernel-default-2.6.5-7.111.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2.
6.5-7.111.i586.rpm -
SuSE kernel-default-2.6.5-7.111.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-defaul
t-2.6.5-7.111.x86_64.rpm - SuSE kern
参考网址
来源: XF
名称: linux-ip-packet-dos(17800)
链接:http://xforce.iss.net/xforce/xfdb/17800
来源: BID
名称: 11488
链接:http://www.securityfocus.com/bid/11488
来源: SUSE
名称: SUSE-SA:2004:037
链接:http://www.novell.com/linux/security/advisories/2004_37_kernel.html
来源: SECUNIA
名称: 11202
链接:http://secunia.com/advisories/11202/
来源: MANDRAKE
名称: MDKSA-2005:022
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:022