OSVDB ID: 33028

Title: Linux Kernel conntrack IPv6 Packet Reassembly Ruleset Bypass

Info

Disclosure

Mar 07, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

The Linux Kernel contains a flaw that may allows a remote attacker to bypass certain netfilter rulesets. The issue is due to the 'nf_conntrack' function not copying 'nfctinfo' information resulting in IPv6 fragments are treated as established and could allow an attacker to bypass a ruleset that accepts established packets.

Classification

Location: Remote / Network Access
Attack Type: Infrastructure
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 2.6.20.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Linux

Kernel

2.6.20.3
2.6.20.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/33028