Total vulnerabilities in the database
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
Software | From | Fixed in |
---|---|---|
google / android | - | 7.0.x |
oracle / vm_server | 3.4 | 3.4.x |
oracle / vm_server | 3.3 | 3.3.x |
linux / linux_kernel | - | 4.6.6.x |