CVE Vulnerabilities

CVE-2002-2438

Improper Authentication

Published: May 18, 2021 | Modified: Feb 12, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 2.4.20 (excluding)
Linux Ubuntu upstream *
Linux-fsl-imx51 Ubuntu lucid *
Linux-linaro-omap Ubuntu devel *
Linux-linaro-omap Ubuntu natty *
Linux-linaro-omap Ubuntu oneiric *
Linux-linaro-omap Ubuntu precise *
Linux-linaro-shared Ubuntu devel *
Linux-linaro-shared Ubuntu oneiric *
Linux-linaro-shared Ubuntu precise *
Linux-linaro-vexpress Ubuntu devel *
Linux-linaro-vexpress Ubuntu natty *
Linux-linaro-vexpress Ubuntu oneiric *
Linux-linaro-vexpress Ubuntu precise *
Linux-lts-backport-maverick Ubuntu lucid *
Linux-mvl-dove Ubuntu lucid *
Linux-qcm-msm Ubuntu devel *
Linux-qcm-msm Ubuntu lucid *
Linux-qcm-msm Ubuntu natty *
Linux-qcm-msm Ubuntu oneiric *
Linux-qcm-msm Ubuntu precise *

Potential Mitigations

References