CVE-2012-2663
published 2014-02-15CVE-2012-2663: extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.85%
85.1th percentile
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iptables | — | — |
| debian | linux | < linux 3.2.29-1 (bookworm) | linux 3.2.29-1 (bookworm) |
| linux | linux_kernel | < 3.0.38 | 3.0.38 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 3.1 < 3.2.24 | 3.2.24 |
| netfilter | iptables | <= 1.4.21 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-2663: iptables - extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN pac...
vendor_debian·2012·CVSS 7.5
CVE-2012-2663 [HIGH] CVE-2012-2663: iptables - extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN pac...
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2012-6638: linux - The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel b...
vendor_debian·2012·CVSS 7.5
CVE-2012-6638 [HIGH] CVE-2012-6638: linux - The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel b...
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.
Scope: local
bookworm: resolved (fixed in 3.2.29-1)
bullseye: resolved (fixed in 3.2.29-1)
forky: resolved (fixed in 3.2.29-1)
sid: resolved (fixed in 3.2.29-1)
trixie: resolved (fixed in 3.2.29-1)
Red Hat
iptables: --syn flag bypass
vendor_redhat·2011-12-02·CVSS 7.5
CVE-2012-2663 [HIGH] iptables: --syn flag bypass
iptables: --syn flag bypass
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
Statement: This issue does affect Red Hat Enterprise Linux 5 and 6.
The risks in breaking compatability associated with fixing this flaw outweigh the benefits of the fix, therefore Red Hat does not plan to fix this flaw in Red Hat Enterprise Linux 5 and 6.
Please note that the remote DoS issue in the way how Linux kernel treats SYN+FIN flags set is being handled under different CVE, CVE-2012-6638, and is planned to be fixed in all affected Red Hat Enterprise Linux releases.
Mitigation: Instead of --syn use
Red Hat
Kernel: net: tcp: potential DoS via SYN+FIN messages
vendor_redhat·2011-12-02·CVSS 7.5
CVE-2012-6638 [HIGH] Kernel: net: tcp: potential DoS via SYN+FIN messages
Kernel: net: tcp: potential DoS via SYN+FIN messages
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.
Statement: This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
GHSA
GHSA-wq3v-5978-56ch: The tcp_rcv_state_process function in net/ipv4/tcp_input
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2012-6638 [HIGH] CWE-400 GHSA-wq3v-5978-56ch: The tcp_rcv_state_process function in net/ipv4/tcp_input
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.
GHSA
GHSA-g725-p8m6-82j4: extensions/libxt_tcp
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2012-2663 [HIGH] GHSA-g725-p8m6-82j4: extensions/libxt_tcp
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
OSV
CVE-2012-2663: extensions/libxt_tcp
osv·2014-02-15·CVSS 7.5
CVE-2012-2663 [HIGH] CVE-2012-2663: extensions/libxt_tcp
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
OSV
CVE-2012-6638: The tcp_rcv_state_process function in net/ipv4/tcp_input
osv·2014-02-15·CVSS 7.5
CVE-2012-6638 [HIGH] CVE-2012-6638: The tcp_rcv_state_process function in net/ipv4/tcp_input
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2663 iptables: --syn flag bypass
bugzilla·2012-05-30·CVSS 7.5
CVE-2012-2663 [HIGH] CVE-2012-2663 iptables: --syn flag bypass
CVE-2012-2663 iptables: --syn flag bypass
Originally reported as a DoS related issue:
http://git.kernel.org/?p=linux/kernel/git/davem/net-next.git;a=commitdiff;h=fdf5af0daf8019cec2396cdef8fb042d80fe71fa
Denys Fedoryshchenko reported that SYN+FIN attacks were bringing his
linux machines to their limits.
Dont call conn_request() if the TCP flags includes SYN flag
---
This issue also allows bypass of --syn rules in iptables:
http://www.spinics.net/lists/netfilter-devel/msg21248.html
Unfortunately, with current stable Linux kernel release (as well as
with most of the previous versions) blocking TCP packets with the SYN
bit set and the ACK,RST and FIN bits cleared won't prevent incoming
TCP connections.
It should be noted that the combination of SYN+FIN in a TCP-IP packet is generally
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
2014-02-15
Published