Home » Hacking News » Caldera OpenLinux TCP packet filtering weakness
Caldera OpenLinux TCP packet filtering weakness
by Mario Miri on May 16th, 2003 A weakness has been discovered in OpenLinux tcp_sec implementations while filtering TCP packets. Specifically, an attacker may be capable of bypassing network firewall policies by setting both the SYN and FIN flags within a malformed TCP packet. This may make it possible for an attacker to establish a session with a service that could otherwise be inaccessible.
Vulnerable:
Caldera OpenLinux Server 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Workstation 3.1.1
Solution:
Security advisory released contains further fix information:
CSSA-2003-019.0
Discovered by:
Paul Starzetz, [email protected]