Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 26105 - [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)
Summary: [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://www.netfilter.org/security/200...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-08-06 23:49 UTC by Martin Holzer (RETIRED)
Modified: 2003-09-22 00:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Holzer (RETIRED) gentoo-dev 2003-08-06 23:49:52 UTC
Date: Sat, 2 Aug 2003 16:34:17 +0200
From: Netfilter Core Team 
To: Netfilter Announcement List 
Cc: vendor-sec@lst.de, bugtraq@securityfocus.com, lwn@lwn.net
Subject: [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)

                  Netfilter Core Team Security Advisory
                  
                           CVE: CAN-2003-0467

Subject:

  Netfilter / NAT Remote DoS

Released:

  01 Aug 2003

Effects:

  Under limited circumstances, a remote user may be able to crash a
  machine doing Network Address Translation (NAT).

Estimated Severity:

  Medium.

Systems Affected:

  Linux 2.4.20 kernels and recent 2.5 kernels with
  CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC enabled, or the
  ip_nat_ftp or ip_nat_irc modules loaded, on which ftp and irc users
  are not packet filtered out.

Solution:

  BEST: Upgrade to Linux kernels 2.4.21 (stable), or apply the patch below.

  OR: As a workaround, the modules can be removed, or iptables can
  be used to block untrusted users from initiating ftp or irc
  connections through the NAT machine.

Details:

  This was verified by Rusty Russell on 2.4.20, and verified fixed
  with this patch.

Vendor Statement:

  Red Hat: All of the 2.4.20-based kernels shipped by Red Hat already
           contain the patch and are not vulnerable to this issue.
  Others:  unknown

Credits:
  The problem was found, and the fix implemented by the Netfilter Core Team.

Contact:
  coreteam@netfilter.org


patch is on the URL
Comment 1 Daniel Ahlberg (RETIRED) gentoo-dev 2003-08-07 19:08:09 UTC
Same as #26106 
Comment 2 solar (RETIRED) gentoo-dev 2003-09-22 00:19:35 UTC
This was fixed and is also for two kernel revisions ago. 
changing resolution to FIXED