CVE-2002-2254

Linux Kernel 2.4-2.4.19 and 2.5-2.5.31 - Unauthorized Network Traffic Access via Netfilter IP Packet Queuing

Title source: llm
STIX 2.1

Description

The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network traffic that would otherwise be restricted.

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-12/0025.html
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6305
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10756

Scores

EPSS 0.0036
EPSS Percentile 29.2%

Details

CWE
CWE-264
Status published
Products (22)
linux/linux_kernel 2.4.0 (13 CPE variants)
linux/linux_kernel 2.4.1
linux/linux_kernel 2.4.10
linux/linux_kernel 2.4.11 (2 CPE variants)
linux/linux_kernel 2.4.12
linux/linux_kernel 2.4.13
linux/linux_kernel 2.4.14
linux/linux_kernel 2.4.15
linux/linux_kernel 2.4.16
linux/linux_kernel 2.4.17
... and 12 more
Published Dec 31, 2002
Tracked Since Feb 18, 2026