Vulnerability CVE-2013-2232


Published: 2013-07-04   Modified: 2013-07-05

Description:
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Linux Kernel ipv4 vs ipv6 structure during routing lookup in sendmsg
Marcus Meissner
03.07.2013

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Linux -> Linux kernel 

 References:
https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
https://github.com/torvalds/linux/commit/a963a37d384d71ad43b3e9e79d68d42fbe0901f3
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a963a37d384d71ad43b3e9e79d68d42fbe0901f3
http://www.ubuntu.com/usn/USN-1947-1
http://www.ubuntu.com/usn/USN-1946-1
http://www.ubuntu.com/usn/USN-1945-1
http://www.ubuntu.com/usn/USN-1944-1
http://www.ubuntu.com/usn/USN-1943-1
http://www.ubuntu.com/usn/USN-1942-1
http://www.ubuntu.com/usn/USN-1941-1
http://www.ubuntu.com/usn/USN-1938-1
http://www.ubuntu.com/usn/USN-1913-1
http://www.ubuntu.com/usn/USN-1912-1
http://www.openwall.com/lists/oss-security/2013/07/02/5
http://www.debian.org/security/2013/dsa-2766
http://rhn.redhat.com/errata/RHSA-2013-1173.html
http://rhn.redhat.com/errata/RHSA-2013-1166.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html

Copyright 2024, cxsecurity.com

 

Back to Top