Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux NetFilter NAT信息泄露漏洞
Vulnerability Description
Linux内核是Linux操作系统的核心部分,其中Netfilter是Linux内核的一个通用防火墙架构的实现。 Netfilter的NAT功能实现存在漏洞,可导致远程攻击者获得被NAT(地址或端口转换)后主机的端口信息。 攻击者可以小TTL值的TCP包给远程防火墙的特定端口,当此包路由到达防火墙并经过其NAT转换以后最终到达接收此包的主机时,主机会产生ICMP TTL过期的应答,ICMP包中的端口信息将不被NAT系统转换过后就直接回传,即应答的ICMP包回包含实际主机的端口信息。这可能导致远程攻击者收集
CVSS Information
N/A
Vulnerability Type
N/A