OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: [suse-security] Fw: IP Masq question
From: john scroggins (dataefxearthlink.net)
Date: Mon May 01 2000 - 04:37:37 CDT


I guess the security announcement was my reply? hmm...

Check the hyperlink for complete details of the problem

Cheers

John
----- Original Message -----
From: john scroggins
To: marcsuse.de
Sent: Saturday, April 29, 2000 12:51 AM
Subject: IP Masq question

Hi Marc,

I read this post and was wondering how this affects the SuSE 6.3 platform,

SECURITYFOCUS.COM: MULTIPLE LINUX VENDOR 2.2.X KERNEL IP
MASQUERADING VULNERABILITIES

"A serious vulnerability exists in the IP Masquerading code
present in, but not necessarily limited to, the 2.2.x Linux
kernel. Due to poor checking of connections in the kernel code,
an attacker can potentially rewrite the UDP masquerading entries,
making it possible for UDP packets to be routed back to the
internal machine."

COMPLETE STORY:
http://www.securityfocus.com/bid/1078

TIA

Cheers,

John