Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1583

Опубликовано: 17 апр. 2012
Источник: redhat
CVSS2: 7.8

Описание

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

Отчет

This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-0480.html. A future kernel update for Red Hat Enterprise Linux 4 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelWill not fix
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelAffected
Red Hat Enterprise Linux 5kernelFixedRHSA-2012:048017.04.2012
Red Hat Enterprise Linux 5.6 EUS - Server OnlykernelFixedRHSA-2012:072012.06.2012

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-393->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=752304kernel: ipv6: panic using raw sockets

7.8 High

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

nvd
больше 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

debian
больше 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6 ...

github
больше 3 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

oracle-oval
почти 14 лет назад

ELSA-2012-0480: kernel security, bug fix, and enhancement update (IMPORTANT)

7.8 High

CVSS2