UBUNTU-CVE-2014-8160
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-8160
UBUNTU-CVE-2014-8160
Summary:
Details: net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
References: https://ubuntu.com/security/CVE-2014-8160, http://www.spinics.net/lists/netfilter-devel/msg33430.html, https://ubuntu.com/security/notices/USN-2513-1, https://ubuntu.com/security/notices/USN-2514-1, https://ubuntu.com/security/notices/USN-2515-1, https://ubuntu.com/security/notices/USN-2516-1, https://ubuntu.com/security/notices/USN-2517-1, https://ubuntu.com/security/notices/USN-2518-1, https://www.cve.org/CVERecord?id=CVE-2014-8160
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
