imPC@ndo IT

Tracker / CVE-2014-8160

CVE-2014-8160

Medium 5.0

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · … → 3.18
opensuse opensuse
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_eus
redhat enterprise_linux_server_tus
redhat enterprise_linux_workstation
suse linux_enterprise_desktop
suse linux_enterprise_real_time_extension
suse linux_enterprise_server
suse linux_enterprise_software_development_kit
suse linux_enterprise_workstation_extension

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References