DetailsA security hole has been found that does not affect the default A vulnerability in iptables "RELATED" connection tracking has been SolutionRed Hat will be releasing a kernel with this and other bugs fixed
shortly. In the meantime, we strongly recommend that users of iptables not allow FTP "RELATED" connections. Updated packagesReferences
http://www.tempest.com.br/advisories/01-2001.html
http://www.securityfocus.com/templates/archive.pike?list=1&mid=177070 http://slashdot.org/comments.pl?sid=01/04/19/047249&cid=36 Keywords
ip_conntrack_ftp
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from: https://www.redhat.com/security/team/key/#package The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/ |