Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6689

Опубликовано: 06 фев. 2015
Источник: redhat
CVSS2: 4.4
EPSS Низкий

Описание

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=848949libmnl: incorrect validation of netlink message origin allows attackers to spoof netlink messages

EPSS

Процентиль: 23%
0.0031
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 10 лет назад

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

CVSS3: 7.8
nvd
больше 10 лет назад

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

CVSS3: 7.8
debian
больше 10 лет назад

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux ...

CVSS3: 7.8
github
около 4 лет назад

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

EPSS

Процентиль: 23%
0.0031
Низкий

4.4 Medium

CVSS2