<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>190030</bug_id>
          
          <creation_ts>2007-08-24 11:38 0000</creation_ts>
          <short_desc>net-firewall/nufw &lt; 2.2.4 rule bypass (CVE-2007-4461)</short_desc>
          <delta_ts>2007-08-24 20:46:10 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/26546/</bug_file_loc>
          <status_whiteboard>~4 [noglsa] p-y</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>trivial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>py@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>cedk@gentoo.org</cc>
    
    <cc>netmon@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-24 11:38:03 0000</bug_when>
            <thetext>A security issue has been reported in NuFW, which can be exploited by malicious people to bypass certain security restrictions.

The security issue is caused due to NuFW not correctly dropping packets with an out of period arrival time, which can be exploited to bypass the filtering rules.

The security issue is reported in versions 2.2.x up to but not including 2.2.4.

Solution:
Update to version 2.2.4.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-24 11:40:28 0000</bug_when>
            <thetext>setting status / cc&apos;ing. cedk, please bump as necessary.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cedk@gentoo.org</who>
            <bug_when>2007-08-24 18:43:25 0000</bug_when>
            <thetext>Version bump to 2.2.4 in cvs
Need perhaps to mask the version 2.2.0 ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-08-24 19:40:00 0000</bug_when>
            <thetext>Thx for the quick response cedk. Masking or purging would be nice but not required.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cedk@gentoo.org</who>
            <bug_when>2007-08-24 20:46:10 0000</bug_when>
            <thetext>Remove from cvs</thetext>
          </long_desc>
      
    </bug>

</bugzilla>