Vulnerability Name:

CVE-2005-0449

Assigned:2005-01-24
Published:2005-01-24
Updated:2018-10-03
Summary:The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.1 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-20
References:Source: SGI
Type: UNKNOWN
20060402-01-U

Source: MITRE
Type: CNA
CVE-2005-0449

Source: CONECTIVA
Type: Patch
CLA-2005:945

Source: MLIST
Type: Vendor Advisory
[netdev] 20050124 Re: skb_checksum_help

Source: SECUNIA
Type: Vendor Advisory
19369

Source: SECUNIA
Type: Vendor Advisory
19374

Source: SECUNIA
Type: Vendor Advisory
19607

Source: DEBIAN
Type: UNKNOWN
DSA-1017

Source: DEBIAN
Type: UNKNOWN
DSA-1018

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2005:218

Source: SUSE
Type: Patch, Vendor Advisory
SUSE-SA:2005:018

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2005:283

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2005:284

Source: REDHAT
Type: UNKNOWN
RHSA-2005:293

Source: REDHAT
Type: UNKNOWN
RHSA-2005:366

Source: BID
Type: UNKNOWN
12598

Source: FEDORA
Type: UNKNOWN
FLSA:152532

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10753

Source: UBUNTU
Type: UNKNOWN
USN-82-1

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:2.6.0:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.2:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.3:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.4:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.5:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.6:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.7:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20050449
    V
    CVE-2005-0449
    2015-11-16
    oval:org.mitre.oval:def:10753
    V
    The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
    2013-04-29
    oval:org.debian:def:1018
    V
    several vulnerabilities
    2013-01-21
    oval:org.debian:def:1017
    V
    several vulnerabilities
    2006-03-23
    oval:com.redhat.rhsa:def:20050366
    P
    RHSA-2005:366: kernel security update (Important)
    2005-08-09
    oval:com.redhat.rhsa:def:20050293
    P
    RHSA-2005:293: kernel security update (Important)
    2005-05-13
    BACK
    linux linux kernel 2.6.0
    linux linux kernel 2.6.1
    linux linux kernel 2.6.2
    linux linux kernel 2.6.3
    linux linux kernel 2.6.4
    linux linux kernel 2.6.5
    linux linux kernel 2.6.6
    linux linux kernel 2.6.7
    linux linux kernel 2.6.8