Jolla is vulnerable to double direct ICMP spoofing
The first notification is at, but I can not open it: https://together.jolla.com/question/65928/is-jolla-vulnerable-to-double-direct-icmp-spoofing/
At that time there was no vulnerability, but there is now (1.1.1.27, Vaarainjärvi):
[root@Jolla nemo]# cat /proc/sys/net/ipv4/conf/all/accept_redirects
1
For more information: http://blog.zimperium.com/doubledirect-zimperium-discovers-full-duplex-icmp-redirect-attacks-in-the-wild/
I can ask for a fix it?
BUMP this is important!
misc11 ( 2015-01-21 12:22:46 +0200 )edit