7.5
CVSSv2

CVE-2005-2317

Published: 19/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Shorewall 2.4.x prior to 2.4.1, 2.2.x prior to 2.2.5, and 2.0.x prior to 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.

Vulnerable Product Search on Vulmon Subscribe to Product

shorewall shorewall 2.0.14

shorewall shorewall 2.0.15

shorewall shorewall 2.0.16

shorewall shorewall 2.0.2

shorewall shorewall 2.0.6

shorewall shorewall 2.0.7

shorewall shorewall 2.0.8

shorewall shorewall 2.0.9

shorewall shorewall 2.0.0

shorewall shorewall 2.0.0a

shorewall shorewall 2.0.0b

shorewall shorewall 2.0.2e

shorewall shorewall 2.0.2f

shorewall shorewall 2.0.3

shorewall shorewall 2.0.3a

shorewall shorewall 2.4.0

shorewall shorewall 2.4.0_rc1

shorewall shorewall 2.4.0_rc2

shorewall shorewall 2.0.10

shorewall shorewall 2.0.12

shorewall shorewall 2.0.2b

shorewall shorewall 2.0.2d

shorewall shorewall 2.0.3b

shorewall shorewall 2.0.4

shorewall shorewall 2.2.1

shorewall shorewall 2.2.3

shorewall shorewall 2.0.1

shorewall shorewall 2.0.11

shorewall shorewall 2.0.13

shorewall shorewall 2.0.2a

shorewall shorewall 2.0.2c

shorewall shorewall 2.0.3c

shorewall shorewall 2.0.5

shorewall shorewall 2.2.0

shorewall shorewall 2.2.2

shorewall shorewall 2.2.4

Vendor Advisories

A firewall bypass vulnerability has been found in shorewall If MACLIST_TTL was set to a value greater than 0 or MACLIST_DISPOSITION was set to “ACCEPT” in /etc/shorewall/shorewallconf, and a client was positively identified through its MAC address, that client bypassed all other policies/rules in place This could allow external computers to ...
"Supernaut" noticed that shorewall, the Shoreline Firewall, could generate an iptables configuration which is significantly more permissive than the rule set given in the shorewall configuration, if MAC verification are used in a non-default manner When MACLIST_DISPOSITION is set to ACCEPT in the shorewallconf file, all packets from hosts which f ...