The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17960 | vdb entry third party advisory |
http://www.osvdb.org/11407 | vdb entry broken link |
http://www.astaro.org/showflat.php?Cat=&Number=51459&page=0&view=collapsed&sb=5&o=&fpart=1#51459 | patch broken link |
http://secunia.com/advisories/13089 | broken link third party advisory patch vendor advisory |
http://securitytracker.com/id?1012065 | vdb entry third party advisory broken link |