CVE-2016-5696
CVE-2016-5696
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=75ff39ccc1bd5d3c455b6822ab09e533c551f758http://rhn.redhat.com/errata/RHSA-2016-1631.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1632.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1633.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1657.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1664.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1814.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1815.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1939.htmlhttps://bto.bluecoat.com/security-advisory/sa131https://bugzilla.redhat.com/show_bug.cgi?id=1354708https://github.com/Gnoxter/mountain_goat