Linux是一款开放源代码操作系统。 Linux内核包含的iptables不正确处理部分TCP头字段值,远程攻击者可以利用这个漏洞对Linux系统进行拒绝服务攻击。 此漏洞只有当在netfilter防火墙子系统中使用"-p tcp --tcp-option"选项时才会被触发。问题存在于tcp_find_option()函数中(net/ipv4/netfilter/ip_tables.c),定义的'opt'字段如下: char opt[60 - sizeof(struct tcphdr)]; 由于不正确处理
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2002-1581 | MailReader.com nph-mr.cgi远程文件泄露漏洞 | |
| CVE-2002-1582 | MailReader.com远程命令执行漏洞 | |
| CVE-2004-0456 | Pavuk远程堆栈缓冲区溢出漏洞 | |
| CVE-2004-0496 | Linux Kernel未明本地权限提升漏洞 | |
| CVE-2004-0497 | Linux Kernel chown()系统调用组属性更改漏洞 | |
| CVE-2004-0577 | Qbik WinGate信息披露漏洞 | |
| CVE-2004-0578 | Qbik WinGate信息披露漏洞 |
No comments yet