Linux Netfilter NAT Remote Denial of Service Vulnerability
BID:8330
Info
Linux Netfilter NAT Remote Denial of Service Vulnerability
| Bugtraq ID: | 8330 |
| Class: | Unknown |
| CVE: |
CVE-2003-0467 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Announced by the Netfilter Core Team. |
| Vulnerable: |
Snapgear Snapgear OS 1.8.4 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Ingate SIParator 3.2 Ingate Firewall 3.2 |
| Not Vulnerable: |
Snapgear Snapgear OS 1.8.5 Linux kernel 2.4.21 Ingate SIParator 3.2.1 Ingate Firewall 3.2.1 |
Discussion
Linux Netfilter NAT Remote Denial of Service Vulnerability
The Netfilter project maintains the packet filter component of the Linux kernel. A fix for a denial of service vulnerability has been reported by the Netfilter project. The vulnerability is present on systems with the ip_nat_ftp or ip_nat_irc modules loaded or with a kernel built supporting options CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC.
The Netfilter project maintains the packet filter component of the Linux kernel. A fix for a denial of service vulnerability has been reported by the Netfilter project. The vulnerability is present on systems with the ip_nat_ftp or ip_nat_irc modules loaded or with a kernel built supporting options CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC.
Exploit / POC
Linux Netfilter NAT Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Netfilter NAT Remote Denial of Service Vulnerability
Solution:
This issue can be fixed by upgrading to the 2.4.21 kernel or later. A source code patch for 2.4.21pre7 is also available.
Ingate have released an advisory and upgrades to address this issue. Affected users are advised to upgrade as soon as possible.
Snapgear has released a pre-release (1.8.5) to address this issue.
Snapgear Snapgear OS 1.8.4
Linux kernel 2.4.20
Linux kernel 2.4.21 pre7
Linux kernel 2.4.21 pre4
Linux kernel 2.4.21 pre1
Ingate SIParator 3.2
Ingate Firewall 3.2
Solution:
This issue can be fixed by upgrading to the 2.4.21 kernel or later. A source code patch for 2.4.21pre7 is also available.
Ingate have released an advisory and upgrades to address this issue. Affected users are advised to upgrade as soon as possible.
Snapgear has released a pre-release (1.8.5) to address this issue.
Snapgear Snapgear OS 1.8.4
-
Snapgear Snapgear OS 1.8.5
http://www.snapgear.com/downloads.html
Linux kernel 2.4.20
-
Linux linux-2.4.21.tar.bz2
http://www.kernel.org/pub/linux/kernel/v2.4/linux-2.4.21.tar.bz2
Linux kernel 2.4.21 pre7
-
Linux linux-2.4.21.tar.bz2
http://www.kernel.org/pub/linux/kernel/v2.4/linux-2.4.21.tar.bz2 -
Netfilter netfilter-ircftp-nat.patch
http://downloads.securityfocus.com/vulnerabilities/patches/netfilter-i rcftp-nat.patch
Linux kernel 2.4.21 pre4
-
Linux linux-2.4.21.tar.bz2
http://www.kernel.org/pub/linux/kernel/v2.4/linux-2.4.21.tar.bz2
Linux kernel 2.4.21 pre1
-
Linux linux-2.4.21.tar.bz2
http://www.kernel.org/pub/linux/kernel/v2.4/linux-2.4.21.tar.bz2
Ingate SIParator 3.2
-
Ingate Ingate Firewall 3.2.1 and Ingate SIParator 3.2.1
http://www.ingate.com/relnote-321.php
Ingate Firewall 3.2
-
Ingate Ingate Firewall 3.2.1 and Ingate SIParator 3.2.1
http://www.ingate.com/relnote-321.php
References
Linux Netfilter NAT Remote Denial of Service Vulnerability
References:
References: