OpenBSD PF State Tracking Spoofed Packet Vulnerability
BID:9362
Info
OpenBSD PF State Tracking Spoofed Packet Vulnerability
| Bugtraq ID: | 9362 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2004 12:00AM |
| Updated: | Jan 05 2004 12:00AM |
| Credit: | Discovery credited to Darren Reed. |
| Vulnerable: |
OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 OpenBSD OpenBSD 3.2 OpenBSD OpenBSD 3.1 OpenBSD OpenBSD 3.0 |
| Not Vulnerable: | |
Discussion
OpenBSD PF State Tracking Spoofed Packet Vulnerability
A problem in the handling of packets has been reported when stateful inspection is activated. Because of this, it may be possible for an attacker to circumvent traffic filtering by PF.
A problem in the handling of packets has been reported when stateful inspection is activated. Because of this, it may be possible for an attacker to circumvent traffic filtering by PF.
Exploit / POC
OpenBSD PF State Tracking Spoofed Packet Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenBSD PF State Tracking Spoofed Packet Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenBSD PF State Tracking Spoofed Packet Vulnerability
References:
References:
- firewall security bug? (Darren Reed)
- OpenBSD Homepage (OpenBSD)