CVE-2016-5696
CVE-2016-5696
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=75ff39ccc1bd5d3c455b6822ab09e533c551f758http://rhn.redhat.com/errata/RHSA-2016-1631.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1632.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1633.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1657.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1664.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1814.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1815.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1939.htmlhttps://bto.bluecoat.com/security-advisory/sa131https://bugzilla.redhat.com/show_bug.cgi?id=1354708https://github.com/Gnoxter/mountain_goat