Security Flaw with Linux 2.4 Kernel and IPTables

Tempest Security Advisory:
Security Flaw with Linux 2.4 Kernel and IPTables [via Slashdot]

Security Advisory – #01/2001

Security flaw in Linux 2.4 IPTables using FTP PORT

Author: Cristiano Lincoln Mattos, CISSP, SSCP
Systems affected: Firewalls using Linux Kernel 2.4.x with IPTables

Release date: 16 April 2001

Platforms: Linux Kernel 2.4.x

Impact: If an attacker can establish an FTP connection passing through a Linux 2.4.x IPTables firewall with the state options allowing “related” connections (almost 100% do), he can insert entries into the firewall’s connection tables…

Leave a Reply