Re: Security issues in 2.4.9 and beyond

From: Florian Weimer (Florian.Weimer@RUS.Uni-Stuttgart.DE)
Date: Tue Dec 18 2001 - 13:04:14 EST


Martin Josefsson <gandalf@wlug.westbo.se> writes:

> > This is what I have so far for 2.4.9:
> > 1. Netfilter mac address matching bug
> > 2. ptrace race condition
> > 3. symlink DoS
> > 4. syncookie/netfilter bug
> > 5. Netfilter FTP conntrack bug (can someone confirm this ??)
>
> #5 was fixed in 2.4.5 I believe.

There are rumours about a buffer overflow in the PASV command, which
was silently fixed (it's not related to earlier FTP connection
tracking problems which could lead to filter evasion).

-- 
Florian Weimer 	                  Florian.Weimer@RUS.Uni-Stuttgart.DE
University of Stuttgart           http://cert.uni-stuttgart.de/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sun Dec 23 2001 - 21:00:17 EST