Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2189

Опубликовано: 10 окт. 2011
Источник: debian
EPSS Низкий

Описание

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linux-2.6fixed2.6.35-1package
linux-2.6no-dsalennypackage
linux-2.6no-dsasqueezepackage
vsftpdfixed2.3.4-1package
vsftpdfixed2.3.2-3+squeeze2squeezepackage
vsftpdfixed2.0.7-1+lenny1lennypackage

Примечания

  • this is technically a kernel bug. however this has been workarounded specifically

  • for vsftpd by adding a kernel check before using this feature, see DSA-2304-1

  • for details

EPSS

Процентиль: 91%
0.07252
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 14 лет назад

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

redhat
почти 15 лет назад

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

CVSS3: 7.5
nvd
около 14 лет назад

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

CVSS3: 7.5
github
больше 3 лет назад

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

fstec
почти 15 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 91%
0.07252
Низкий