Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1583

Опубликовано: 17 апр. 2012
Источник: redhat
CVSS2: 7.8
EPSS Низкий

Описание

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

Отчет

This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-0480.html. A future kernel update for Red Hat Enterprise Linux 4 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelWill not fix
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelAffected
Red Hat Enterprise Linux 5kernelFixedRHSA-2012:048017.04.2012
Red Hat Enterprise Linux 5.6 EUS - Server OnlykernelFixedRHSA-2012:072012.06.2012

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-393->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=752304kernel: ipv6: panic using raw sockets

EPSS

Процентиль: 79%
0.01364
Низкий

7.8 High

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

nvd
около 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

debian
около 13 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6 ...

github
больше 3 лет назад

Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

oracle-oval
больше 13 лет назад

ELSA-2012-0480: kernel security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 79%
0.01364
Низкий

7.8 High

CVSS2