CVE-2005-2317
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2005
Last modified:
03/04/2025
Description
Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:shorewall:shorewall:2.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.0a:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.0b:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2a:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2b:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2c:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2d:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2e:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.2f:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.3a:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.3b:*:*:*:*:*:*:* | ||
cpe:2.3:a:shorewall:shorewall:2.0.3c:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/lists/fulldisclosure/2005/Jul/0409.html
- http://secunia.com/advisories/16087
- http://secunia.com/advisories/17110
- http://secunia.com/advisories/17113
- http://shorewall.net/News.htm#20050717
- http://www.debian.org/security/2005/dsa-849
- http://www.gentoo.org/security/en/glsa/glsa-200507-20.xml
- http://www.securityfocus.com/bid/14292
- http://www.ubuntu.com/usn/usn-197-1
- http://seclists.org/lists/fulldisclosure/2005/Jul/0409.html
- http://secunia.com/advisories/16087
- http://secunia.com/advisories/17110
- http://secunia.com/advisories/17113
- http://shorewall.net/News.htm#20050717
- http://www.debian.org/security/2005/dsa-849
- http://www.gentoo.org/security/en/glsa/glsa-200507-20.xml
- http://www.securityfocus.com/bid/14292
- http://www.ubuntu.com/usn/usn-197-1