[12037] in bugtraq

home help back first fref pref prev next nref lref last post

Re: [EuroHaCk] Linux 2.2.x ISN vulnerability (fwd)

daemon@ATHENA.MIT.EDU (Jeremy Buhler)
Tue Sep 28 15:22:29 1999

Message-Id:  <19990928002207.7784.qmail@securityfocus.com>
Date:         Tue, 28 Sep 1999 00:22:07 -0000
Reply-To: Jeremy Buhler <jbuhler@SPEAKEASY.ORG>
From: Jeremy Buhler <jbuhler@SPEAKEASY.ORG>
X-To:         bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <Pine.LNX.4.10.9909270031050.23786-100000@localhost.localdomain>

> A weakness within the TCP stack in Linux 2.2.x kernels 
> has been discovered. The vulnerability makes it possible
> to "blind-spoof" TCP connections.

This vulnerability is fixed in kernels 2.2.13pre13 and
later.  Hopefully 2.2.13 will be released shortly and/or
the relevant patch from pre13 will be released as an
erratum versus 2.2.12.  Alan?

home help back first fref pref prev next nref lref last post