Re: Linux 2.2.x ISN Vulnerability

kuznet@ms2.inr.ac.ru
Sun, 26 Sep 1999 23:16:16 +0400 (MSK DST)


Hello!

> With the typo-bug fixed, the random part of the secret would be unknown.
> So in the bug-free case (aka pre-2.2.13/2.3.18ac8), the attacker can't
> know the whole secret,

It can. Reread the report.

The bug was that remote destination was ignored in calculating
seqno, so that all the destinations shared one secret.

Alexey

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/