Lucene search

K
fortinetFortiGuard LabsFG-IR-16-047
HistoryApr 04, 2017 - 12:00 a.m.

Linux kernel - challenge ack information leak

2017-04-0400:00:00
FortiGuard Labs
www.fortiguard.com
31

0.004 Low

EPSS

Percentile

75.1%

net/ipv4/tcp_input.c in certain Linux kernel versions does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.