Caldera Unknown

Notified:  April 15, 2002 Updated: April 15, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Conectiva Not Affected

Updated:  April 24, 2002

Status

Not Affected

Vendor Statement

Conectiva Linux is not vulnerable to this problem. We only started including a 2.4 kernel in the CL 7.0 version, and the latest kernel version for that distribution is 2.4.12 which does not include the vulnerable code. The upcoming Conectiva Linux 8 uses the 2.4.18 kernel which is also not vulnerable.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Debian Unknown

Notified:  April 15, 2002 Updated: April 15, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Engarde Unknown

Notified:  April 15, 2002 Updated: April 15, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Hewlett Packard Not Affected

Notified:  March 04, 2002 Updated: April 15, 2002

Status

Not Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Hewlett Packard has published the following HP Security Bulletin to address this issue: HPSBTL0203-027 Updated 2.4 kernel available For further information, please visit http://itrc.hp.com and search for the appropriate reference number. Please note that registration may be required to access this document.

MandrakeSoft Affected

Notified:  April 15, 2002 Updated: July 05, 2002

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

MandrakeSoft has published Security Advisory MDKSA-2002:041 to address this vulnerability. For more information, please see http://www.mandrakesecure.net/en/advisories/2002/MDKSA-2002-041.php

Netfilter.org Affected

Notified:  February 27, 2002 Updated: April 24, 2002

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The maintainers of the netfilter kernel subsystem have published a security announcement at: http://www.netfilter.org/security/2002-02-25-irc-dcc-mask.html

Red Hat Inc. Affected

Notified:  February 28, 2002 Updated: April 24, 2002

Status

Affected

Vendor Statement

The Netfilter IRC DCC module is distributed with kernels in Red Hat Linux 7.1 and 7.2, although it is not used in default installations. Updated kernel packages with a fix for this issue are available from the Red Hat Network or linked from our advisory: http://www.redhat.com/support/errata/RHSA-2002-028.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Sequent Unknown

Notified:  April 15, 2002 Updated: April 15, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.