Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12138
HistoryJan 15, 2019 - 9:12 a.m.

TCP Session Hijack

2019-01-1509:12:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.004 Low

EPSS

Percentile

75.1%

kernel-rt is vulnerable to TCP session hijack attacks. The vulnerability exists as net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

References