Jolla is vulnerable to double direct ICMP spoofing

asked 2015-01-21

Tomasz gravatar image

updated 2015-01-21

misc11 gravatar image

The first notification is at, but I can not open it:

At that time there was no vulnerability, but there is now (, Vaarainjärvi):

[root@Jolla nemo]# cat /proc/sys/net/ipv4/conf/all/accept_redirects

For more information:

I can ask for a fix it?

BUMP this is important!

2015-01-21

1 Answer

answered 2015-01-21

tigeli gravatar image

updated 2015-01-27

Will look into this..

EDIT: Yes, on IPv4 the accept_redirects has value of 'true' but then again secure_redirects has also value of 'true' which means that the redirects are only accepted from the gateways defined in the routing table. However for IPv6 there is no secure_redirects therefore we will disable all icmp redirects completely on a future release for both IPv4 and IPv6.

Asked: 2015-01-21

Seen: 945 times

Last updated: Jan 27 '15