Search

published date: March 8, 2002

CVE-2002-0060 : IRC connection tracking helper...

Description

IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions.

Product(s):

  • Linux Kernel Pre9
  • Linux Kernel 2.3.99 pre9
  • Linux Kernel 2.4.18 pre9

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2002-0060, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-0060 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?