Name | CVE-2003-0550 |
Description | The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-358, DSA-423 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
kernel-image-2.4.17-ia64 | source | woody | kernel-image-2.4.17-ia64 | DSA-423 | ||
kernel-image-2.4.18-1-alpha | source | woody | 2.4.18-10. | DSA-358 | ||
kernel-image-2.4.18-1-i386 | source | woody | 2.4.18-11 | DSA-358 | ||
kernel-image-2.4.18-i386bf | source | woody | 2.4.18-5woody4 | DSA-358 | ||
kernel-source-2.4.18 | source | woody | 2.4.18-13 | DSA-358 | ||
kernel-source-2.4.27 | source | (unstable) | (not affected) |
- kernel-source-2.4.27 <not-affected> (Fixed before upload in the archive; 2.4.22-pre3)