LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-04-2003, 11:17 AM   #1
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Rep: Reputation: 46
Etherleak-Vulnerability in Woody ?


I just did a nessus scan (no firewall enabled on the target host) with a 100% up-to-date Woody install. I got a serious vulnerability warning:

Quote:
The remote host is vulnerable to an 'Etherleak' -
the remote ethernet driver seems to leak bits of the
content of the memory of the remote operating system.

Note that an attacker may take advantage of this flaw
only when its target is on the same physical subnet.

See also : http://www.atstake.com/research/advi.../a010603-1.txt
Solution : Contact your vendor for a fix
Risk factor : Serious
CVE : CAN-2003-0001
Nessus ID : 11197

I've been using Knoppix 3.2 from 28th April 2003 ... Nessus 2.01 is installed there.


Does anybody get similar results ?
 
Old 05-04-2003, 01:15 PM   #2
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Original Poster
Rep: Reputation: 46
This got fixed in 2.4.21 ... all versions prior 2.4.21 seem to be vulnerable (incl. 2.4.20)
 
Old 05-05-2003, 11:29 AM   #3
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Original Poster
Rep: Reputation: 46
I just got a reply from the maintainer of the kernel packages:

"This is already patched in the Debian kernels in stable-proposed-updates, testing and unstable."
 
Old 05-05-2003, 02:19 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Well done!
If someone posts other distro's status that'd be appreciated...

Red Hat fixed the padding bug in kernel-2.4.18-26.7*, released 03/20/2003 (RHSA-2003:025-20).

Last edited by unSpawn; 05-06-2003 at 11:17 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
WEP vulnerability true_atlantis Linux - Security 16 02-23-2006 11:23 AM
phpBB Vulnerability Capt_Caveman Linux - Security 6 10-08-2005 12:22 PM
2.6 DoS Vulnerability! /bin/bash Linux - Security 12 06-03-2005 06:45 PM
PHP vulnerability glj Linux - Security 3 03-02-2002 05:47 AM
UPnP vulnerability in XP anoop_chandran General 13 01-08-2002 12:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration