VDB
RHSA-2001%3A142
RHSA-2001%3A142
PUBLISHED
Syncookies are used to protect a system against certain Denial Of Service (DOS) attacks. A flaw in this mechanism has been found which can be used to circumvent certain types of firewall configurations. Note: syncookies are not enabled in the default installation of Red Hat Linux but many server administrators do enable syncookies.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Linux 7.0 | ||
| Red Hat Linux 7.2 | ||
| Red Hat Linux 7.1 | ||
| Red Hat Linux 6.2 |
Timeline
- Nov 2, 2001 CVE Published
- Nov 21, 2025 CVE Updated
- Apr 9, 2026 Distribution Patch
- Apr 9, 2026 Distribution Patch
- Apr 9, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2001:142 advisory
- https://access.redhat.com/security/updates/classification/#important url
- http://cr.yp.to/syncookies.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=54829 url
- https://bugzilla.redhat.com/show_bug.cgi?id=54851 url
- https://bugzilla.redhat.com/show_bug.cgi?id=54868 url
- https://bugzilla.redhat.com/show_bug.cgi?id=55067 url
- https://bugzilla.redhat.com/show_bug.cgi?id=55082 url
- https://bugzilla.redhat.com/show_bug.cgi?id=55097 url
- https://security.access.redhat.com/data/csaf/v2/advisories/2001/rhsa-2001_142.json advisory