Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4162

Опубликовано: 01 июл. 2013
Источник: redhat
CVSS2: 4.9

Описание

The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.

Отчет

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 6 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kernelNot affected
OpenStack 3 for RHEL 6kernelFixedRHSA-2013:152014.11.2013
Red Hat Enterprise Linux 5kernelFixedRHSA-2013:129226.09.2013
Red Hat Enterprise Linux 6kernelFixedRHSA-2013:143616.10.2013
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2013:126416.09.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=987627Kernel: net: panic while pushing pending data out of a IPv6 socket with UDP_CORK enabled

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.

nvd
больше 12 лет назад

The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.

debian
больше 12 лет назад

The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 ...

github
больше 3 лет назад

The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.

fstec
больше 12 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании

4.9 Medium

CVSS2