Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200507-20 ] Shorewall: Security policy bypass
Date: Fri, 22 Jul 2005 05:59:50
Message-Id: 200507220735.59393.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200507-20
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Shorewall: Security policy bypass
9 Date: July 22, 2005
10 Bugs: #99398
11 ID: 200507-20
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in Shorewall allows clients authenticated by MAC
19 address filtering to bypass all other security rules.
20
21 Background
22 ==========
23
24 Shorewall is a high level tool for configuring Netfilter, the firewall
25 facility included in the Linux Kernel.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-firewall/shorewall < 2.4.1 *>= 2.2.5
34 >= 2.4.1
35
36 Description
37 ===========
38
39 Shorewall fails to enforce security policies if configured with
40 "MACLIST_DISPOSITION" set to "ACCEPT" or "MACLIST_TTL" set to a value
41 greater or equal to 0.
42
43 Impact
44 ======
45
46 A client authenticated by MAC address filtering could bypass all
47 security policies, possibly allowing him to gain access to restricted
48 services.
49
50 Workaround
51 ==========
52
53 Set "MACLIST_TTL" to "0" and "MACLIST_DISPOSITION" to "REJECT" in the
54 Shorewall configuration file (usually /etc/shorewall/shorewall.conf).
55
56 Resolution
57 ==========
58
59 All Shorewall users should upgrade to the latest available version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose net-firewall/shorewall
63
64 References
65 ==========
66
67 [ 1 ] CAN-2005-2317
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2317
69 [ 2 ] Shorewall Announcement
70 http://www.shorewall.net/News.htm#20050717
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200507-20.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2005 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.0