CVE-2012-2663
EPSS 0.36%Published: 2/15/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2012-2663
Description
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
Affected packages (1)
- Debian/iptablesfrom 0