Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4348

Опубликовано: 10 янв. 2012
Источник: redhat
CVSS2: 7.1

Описание

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.

Отчет

This issue did not affect the version of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6 and Red Hat Enterprise MRG as they were not vulnerable to CVE-2011-2482. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-0007.html.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 5kernelFixedRHSA-2012:000710.01.2012

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-662->CWE-362->CWE-672->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=757143kernel: incomplete fix for CVE-2011-2482

7.1 High

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.

nvd
около 12 лет назад

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.

debian
около 12 лет назад

Race condition in the sctp_rcv function in net/sctp/input.c in the Lin ...

github
около 3 лет назад

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.

oracle-oval
больше 13 лет назад

ELSA-2012-0007: kernel security, bug fix, and enhancement update (IMPORTANT)

7.1 High

CVSS2