Linux Kernel Promiscuous Mode Status Vulnerability
BID:5304
Info
Linux Kernel Promiscuous Mode Status Vulnerability
| Bugtraq ID: | 5304 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 24 2002 12:00AM |
| Updated: | Jul 24 2002 12:00AM |
| Credit: | Reported by Ricardo Branco <[email protected]>. |
| Vulnerable: |
Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 Linux kernel 2.3.99 Linux kernel 2.3 Linux kernel 2.2.20 Linux kernel 2.2.19 Linux kernel 2.2.18 Linux kernel 2.2.17 Linux kernel 2.2.16 Linux kernel 2.2.15 Linux kernel 2.2.14 Linux kernel 2.2.13 Linux kernel 2.2.12 Linux kernel 2.2.11 Linux kernel 2.2.10 Linux kernel 2.2.9 Linux kernel 2.2.8 Linux kernel 2.2.7 Linux kernel 2.2.6 Linux kernel 2.2.5 Linux kernel 2.2.4 Linux kernel 2.2.3 Linux kernel 2.2.2 Linux kernel 2.2.1 Linux kernel 2.2 |
| Not Vulnerable: | |
Discussion
Linux Kernel Promiscuous Mode Status Vulnerability
The Linux kernel is a freely available, open source kernel originally written by Linus Torvalds. It is the core of all Linux distributions. A potential security risk has been reported in some versions of the Linux Kernel.
The ifconfig utility may be used to determine the state of a network interface. Under some conditions, however, ifconfig may fail to report a network interface that is running in promiscuous mode. This may be the result of the kernel supporting multiple interfaces to the network device, allowing inconsistent behavior.
Exploitation of this vulnerability may allow a malicious local user to disguise some activities. Network interfaces may be placed in promiscuous mode without detection by an administrator, possibly allowing a compromised machine to view internal network traffic.
The Linux kernel is a freely available, open source kernel originally written by Linus Torvalds. It is the core of all Linux distributions. A potential security risk has been reported in some versions of the Linux Kernel.
The ifconfig utility may be used to determine the state of a network interface. Under some conditions, however, ifconfig may fail to report a network interface that is running in promiscuous mode. This may be the result of the kernel supporting multiple interfaces to the network device, allowing inconsistent behavior.
Exploitation of this vulnerability may allow a malicious local user to disguise some activities. Network interfaces may be placed in promiscuous mode without detection by an administrator, possibly allowing a compromised machine to view internal network traffic.
Exploit / POC
Linux Kernel Promiscuous Mode Status Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Kernel Promiscuous Mode Status Vulnerability
Solution:
It has been reported that the ip command included with the iproute2 package will correctly display the promiscuous mode status of a network interface. iproute2 is available at the following location:
ftp://ftp.inr.ac.ru/ip-routing/
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the ip command included with the iproute2 package will correctly display the promiscuous mode status of a network interface. iproute2 is available at the following location:
ftp://ftp.inr.ac.ru/ip-routing/
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linux Kernel Promiscuous Mode Status Vulnerability
References:
References:
- kernel bugs around promiscuous mode setting. (Tatsuo SEKINE)