Linux NetFilter NAT Information Leakage Vulnerability
BID:4699
Info
Linux NetFilter NAT Information Leakage Vulnerability
| Bugtraq ID: | 4699 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2002 12:00AM |
| Updated: | May 08 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Philippe Biondi <[email protected]>. |
| Vulnerable: |
Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 |
| Not Vulnerable: | |
Discussion
Linux NetFilter NAT Information Leakage Vulnerability
The Linux Kernel is the core of all Linux operating systems. It is developed and maintained by public domain.
It is possible for a remote user to discover ports on a firewall that are mapped to systems behind the firewall via NAT. By sending a TCP packet to a port on a system with a TTL less than the total amount of hops to the firewall, when the packet is routed to the host via NAT, a ICMP TTL Expired response will be generated. This response, generated by the host at the end of the NAT rule, will not be translated by the NAT system.
The Linux Kernel is the core of all Linux operating systems. It is developed and maintained by public domain.
It is possible for a remote user to discover ports on a firewall that are mapped to systems behind the firewall via NAT. By sending a TCP packet to a port on a system with a TTL less than the total amount of hops to the firewall, when the packet is routed to the host via NAT, a ICMP TTL Expired response will be generated. This response, generated by the host at the end of the NAT rule, will not be translated by the NAT system.
Exploit / POC
Linux NetFilter NAT Information Leakage Vulnerability
No exploit is required.
No exploit is required.