Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5696

Опубликовано: 06 авг. 2016
Источник: nvd
CVSS3: 4.8
CVSS2: 5.8
EPSS Средний

Описание

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Версия до 7.0 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:oracle:vm_server:3.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_server:3.4:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 4.6.6 (включая)

EPSS

Процентиль: 97%
0.34409
Средний

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 9 лет назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
redhat
около 9 лет назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
debian
около 9 лет назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly ...

CVSS3: 4.8
github
больше 3 лет назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

oracle-oval
около 9 лет назад

ELSA-2016-3595: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 97%
0.34409
Средний

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-200