Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » Caldera OpenLinux TCP packet filtering weakness

Caldera OpenLinux TCP packet filtering weakness

by Mario Miri on May 16th, 2003 A weakness has been discovered in OpenLinux tcp_sec implementations while filtering TCP packets. Specifically, an attacker may be capable of bypassing network firewall policies by setting both the SYN and FIN flags within a malformed TCP packet. This may make it possible for an attacker to establish a session with a service that could otherwise be inaccessible.


Vulnerable:
Caldera OpenLinux Server 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Workstation 3.1.1


Solution:
Security advisory released contains further fix information:
CSSA-2003-019.0


Discovered by:
Paul Starzetz, [email protected]


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »