Vulnerability Name: | CVE-2003-0187 (CCN-12808) | ||||||||
Assigned: | 2003-08-02 | ||||||||
Published: | 2003-08-02 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Netfilter Core Team Security Advisory Sat Aug 02 2003 - 09:33:41 CDT Netfilter Security Advisory: Conntrack list_del() DoS Source: MITRE Type: CNA CVE-2003-0187 Source: BUGTRAQ Type: UNKNOWN 20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS Source: CCN Type: RHSA-2003-172 Updated 2.4 kernel fixes security vulnerabilities and various bugs Source: CCN Type: The Linux Kernel Archives Web site The Linux Kernel Archives Source: CCN Type: OSVDB ID: 6061 Linux IPTables / Netfilter Connection Tracking Linked List DoS Source: CCN Type: BID-8331 Netfilter Connection Tracking Denial of Service Vulnerability Source: XF Type: UNKNOWN netfilter-connectiontracking-dos(12808) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:260 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |