RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
BID:3520
Info
RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
| Bugtraq ID: | 3520 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2001 12:00AM |
| Updated: | Nov 08 2001 12:00AM |
| Credit: | This vulnerability was first published in RedHat advisory RHSA-2001:0144. |
| Vulnerable: |
RedHat Linux 7.2 i386 RedHat Linux 7.1 i386 RedHat Linux 7.1 alpha RedHat iptables-ipv6-1.2.3-1.i386.rpm RedHat iptables-ipv6-1.2.1a-1.i386.rpm RedHat iptables-1.2.3-1.i386.rpm RedHat iptables-1.2.3-1.i386.rpm |
| Not Vulnerable: | |
Discussion
RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
Red Hat Linux is a freely available, Open Source clone of the Unix Operating System. It is distributed and maintained by Red Hat Incorporated.
A problem with the firewall infrastructure included with the Operating System could make it possible for a administrator to unknowingly expose a system to unnecessary risk. The -c option creates a save-file that is not readable by iptables. When iptables attempts to reload the file at system reboot, it will fail.
This makes it possible for an uninformed administrator to leave a system unprotected, and potentially allow access to restricted resources by remote users.
Red Hat Linux is a freely available, Open Source clone of the Unix Operating System. It is distributed and maintained by Red Hat Incorporated.
A problem with the firewall infrastructure included with the Operating System could make it possible for a administrator to unknowingly expose a system to unnecessary risk. The -c option creates a save-file that is not readable by iptables. When iptables attempts to reload the file at system reboot, it will fail.
This makes it possible for an uninformed administrator to leave a system unprotected, and potentially allow access to restricted resources by remote users.
Exploit / POC
RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
No exploit is necessary for this vulnerability.
No exploit is necessary for this vulnerability.
Solution / Fix
RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
Solution:
Vendor fixes available:
RedHat iptables-1.2.3-1.i386.rpm
RedHat iptables-ipv6-1.2.3-1.i386.rpm
RedHat iptables-ipv6-1.2.1a-1.i386.rpm
RedHat Linux 7.1 i386
RedHat Linux 7.1 alpha
RedHat Linux 7.2 i386
Solution:
Vendor fixes available:
RedHat iptables-1.2.3-1.i386.rpm
-
RedHat 7.1 i386 iptables-1.2.4-0.71.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/iptables-1.2.4-0.71.2.i386.rpm
RedHat iptables-ipv6-1.2.3-1.i386.rpm
-
RedHat 7.2 i386 iptables-ipv6-1.2.4-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/iptables-ipv6-1.2.4-2.i386.rpm
RedHat iptables-ipv6-1.2.1a-1.i386.rpm
-
RedHat 7.1 i386 iptables-ipv6-1.2.4-0.71.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/iptables-ipv6-1.2.4-0.71.2.i38 6.rpm
RedHat Linux 7.1 i386
-
RedHat 7.1 i386 iptables-1.2.4-0.71.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/iptables-1.2.4-0.71.2.i386.rpm -
RedHat 7.1 i386 iptables-ipv6-1.2.4-0.71.2.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/iptables-ipv6-1.2.4-0.71.2.i38 6.rpm
RedHat Linux 7.1 alpha
-
RedHat 7.1 alpha iptables-ipv6-1.2.4-0.71.2.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/iptables-ipv6-1.2.4-0.71.2.al pha.rpm
RedHat Linux 7.2 i386
-
RedHat 7.2 i386 iptables-1.2.4-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/iptables-1.2.4-2.i386.rpm -
RedHat 7.2 i386 iptables-ipv6-1.2.4-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/iptables-ipv6-1.2.4-2.i386.rpm
References
RedHat Linux IPTables Save Option Unrestorable Rules Vulnerability
References:
References:
- Updates, Fixes, and Errata Page (RedHat)