Re: Linux 2.2.x ISN Vulnerability

Mr. James W. Laferriere (babydr@baby-dragons.com)
Sun, 26 Sep 1999 14:42:58 -0700 (PDT)


Hello Alexey, I take it that the patch you sent fixes this
condition ? JImL

On Sun, 26 Sep 1999 kuznet@ms2.inr.ac.ru wrote:
> Hello!
> > With the typo-bug fixed, the random part of the secret would be unknown.
> > So in the bug-free case (aka pre-2.2.13/2.3.18ac8), the attacker can't
> > know the whole secret,
> It can. Reread the report.
> The bug was that remote destination was ignored in calculating
> seqno, so that all the destinations shared one secret.
> Alexey
+-----------------------------------------------------------------+
| James W. Laferriere | System Techniques | Give me VMS |
| Network Engineer | 25416 22nd So | Give me Linux |
| babydr@baby-dragons.com | DesMoines WA 98198 | only on AXP |
+-----------------------------------------------------------------+

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/