View previous topic :: View next topic |
Author |
Message |
cerb Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 28 Jun 2002 Posts: 89
|
Posted: Tue Aug 05, 2003 10:47 am Post subject: netfilter: SECURITY ALERT FROM NETFILTER TEAM |
|
|
the netfilter team has released two warnings about severe security issues with conn-tracking and NAT:
http://netfilter.org/security/2003-08-01-listadd.html
http://netfilter.org/security/2003-08-01-nat-sack.html
these only affect kernel 2.4.20 - and since 2.4.20-gentoo-r5 was around for a long time, i am wondering if the fixes (known to exist for months as it seems) have been implemented yet? or will there be a 2.4.21-gentoo-rsomething ebuild soon?
-c _________________ Linux is a wigwam - no Windows, no Gates, Apache inside ![Smile :-)](images/smiles/icon_smile.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
cerb Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 28 Jun 2002 Posts: 89
|
Posted: Tue Aug 05, 2003 11:40 am Post subject: |
|
|
doesn't this affect *anybody* ? _________________ Linux is a wigwam - no Windows, no Gates, Apache inside ![Smile :-)](images/smiles/icon_smile.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
patrickfo Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 30 Jun 2002 Posts: 79 Location: France
|
Posted: Tue Aug 05, 2003 11:58 am Post subject: patch certainly applied |
|
|
i you download the proposed patch from the first link and try to apply it with patch --dry-run you will see that it is applied on gentoo-sources
patrick |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
cerb Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 28 Jun 2002 Posts: 89
|
Posted: Tue Aug 05, 2003 3:24 pm Post subject: |
|
|
thanks _________________ Linux is a wigwam - no Windows, no Gates, Apache inside ![Smile :-)](images/smiles/icon_smile.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Simba n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
![](images/avatars/d52f16833dcc31f25bb2f.jpg)
Joined: 08 Nov 2002 Posts: 60
|
Posted: Wed Aug 06, 2003 3:42 pm Post subject: |
|
|
But my last kernel xfs-sources vers. 2.4.20-r3 still doesn't have this patch! ( |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
patrickfo Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 30 Jun 2002 Posts: 79 Location: France
|
Posted: Wed Aug 06, 2003 4:27 pm Post subject: arghh!!! |
|
|
you can cut and paste the patch to a file, say netfilter.patch...
then do :
cd /usr/src/linux
cat netfilter.patch | patch -p1 -E --dry-run
and if all is ok ( no errors founds...), you re do it without the --dry-run option
and then rebuild your kernel...
good-luck
patrick |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|