CVE-2005-2873 Information

Description

The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX which can cause ipt_recent netfilter rules to block too early a different vulnerability than CVE-2005-2872.

Reference

http://blog.blackdown.de/2005/05/09/fixing-the-ipt_recent-netfilter-module/ http://rhn.redhat.com/errata/RHBA-2007-0304.html http://secunia.com/advisories/17826 http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 http://www.securityfocus.com/bid/14791 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9838

Share on: