CVE-2012-2663
EPSS 2.8%
Description
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
How to fix CVE-2012-2663
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/iptables—no fix listed
Is CVE-2012-2663 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0