extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in –syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iptables | Netfilter | * | 1.4.21 (including) |
Iptables | Ubuntu | artful | * |
Iptables | Ubuntu | bionic | * |
Iptables | Ubuntu | cosmic | * |
Iptables | Ubuntu | devel | * |
Iptables | Ubuntu | disco | * |
Iptables | Ubuntu | eoan | * |
Iptables | Ubuntu | esm-infra-legacy/trusty | * |
Iptables | Ubuntu | esm-infra/bionic | * |
Iptables | Ubuntu | esm-infra/xenial | * |
Iptables | Ubuntu | focal | * |
Iptables | Ubuntu | hardy | * |
Iptables | Ubuntu | lucid | * |
Iptables | Ubuntu | natty | * |
Iptables | Ubuntu | oneiric | * |
Iptables | Ubuntu | precise | * |
Iptables | Ubuntu | precise/esm | * |
Iptables | Ubuntu | quantal | * |
Iptables | Ubuntu | raring | * |
Iptables | Ubuntu | saucy | * |
Iptables | Ubuntu | trusty | * |
Iptables | Ubuntu | trusty/esm | * |
Iptables | Ubuntu | upstream | * |
Iptables | Ubuntu | utopic | * |
Iptables | Ubuntu | vivid | * |
Iptables | Ubuntu | vivid/stable-phone-overlay | * |
Iptables | Ubuntu | vivid/ubuntu-core | * |
Iptables | Ubuntu | wily | * |
Iptables | Ubuntu | xenial | * |
Iptables | Ubuntu | yakkety | * |
Iptables | Ubuntu | zesty | * |