Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-6657

Опубликовано: 28 сент. 2014
Источник: nvd
CVSS2: 4.9
EPSS Низкий

Описание

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 3.5.6 (включая)
cpe:2.3:o:linux:linux_kernel:3.5.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.5.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.5.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.5.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.5.5:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:novell:suse_linux_enterprise_server:10.0:sp4:*:*:ltss:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp1:*:*:ltss:*:*:*

EPSS

Процентиль: 32%
0.00122
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 10 лет назад

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

redhat
больше 12 лет назад

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

debian
больше 10 лет назад

The sock_setsockopt function in net/core/sock.c in the Linux kernel be ...

github
около 3 лет назад

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

oracle-oval
больше 10 лет назад

ELSA-2014-3108: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 32%
0.00122
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264