Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
netfilter: SECURITY ALERT FROM NETFILTER TEAM
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
cerb
Tux's lil' helper
Tux's lil' helper


Joined: 28 Jun 2002
Posts: 89

PostPosted: Tue Aug 05, 2003 10:47 am    Post subject: netfilter: SECURITY ALERT FROM NETFILTER TEAM Reply with quote

the netfilter team has released two warnings about severe security issues with conn-tracking and NAT:

http://netfilter.org/security/2003-08-01-listadd.html

http://netfilter.org/security/2003-08-01-nat-sack.html

these only affect kernel 2.4.20 - and since 2.4.20-gentoo-r5 was around for a long time, i am wondering if the fixes (known to exist for months as it seems) have been implemented yet? or will there be a 2.4.21-gentoo-rsomething ebuild soon?

-c
_________________
Linux is a wigwam - no Windows, no Gates, Apache inside :-)
Back to top
View user's profile Send private message
cerb
Tux's lil' helper
Tux's lil' helper


Joined: 28 Jun 2002
Posts: 89

PostPosted: Tue Aug 05, 2003 11:40 am    Post subject: Reply with quote

doesn't this affect *anybody* ?
_________________
Linux is a wigwam - no Windows, no Gates, Apache inside :-)
Back to top
View user's profile Send private message
patrickfo
Tux's lil' helper
Tux's lil' helper


Joined: 30 Jun 2002
Posts: 79
Location: France

PostPosted: Tue Aug 05, 2003 11:58 am    Post subject: patch certainly applied Reply with quote

i you download the proposed patch from the first link and try to apply it with patch --dry-run you will see that it is applied on gentoo-sources
patrick
Back to top
View user's profile Send private message
cerb
Tux's lil' helper
Tux's lil' helper


Joined: 28 Jun 2002
Posts: 89

PostPosted: Tue Aug 05, 2003 3:24 pm    Post subject: Reply with quote

thanks
_________________
Linux is a wigwam - no Windows, no Gates, Apache inside :-)
Back to top
View user's profile Send private message
Simba
n00b
n00b


Joined: 08 Nov 2002
Posts: 60

PostPosted: Wed Aug 06, 2003 3:42 pm    Post subject: Reply with quote

But my last kernel xfs-sources vers. 2.4.20-r3 still doesn't have this patch! :((
Back to top
View user's profile Send private message
patrickfo
Tux's lil' helper
Tux's lil' helper


Joined: 30 Jun 2002
Posts: 79
Location: France

PostPosted: Wed Aug 06, 2003 4:27 pm    Post subject: arghh!!! Reply with quote

you can cut and paste the patch to a file, say netfilter.patch...
then do :
cd /usr/src/linux
cat netfilter.patch | patch -p1 -E --dry-run
and if all is ok ( no errors founds...), you re do it without the --dry-run option
and then rebuild your kernel...
good-luck
patrick
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum