Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2924

Опубликовано: 02 апр. 2015
Источник: redhat
CVSS2: 3.3

Описание

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

A flaw was found in the way NetworkManager handled router advertisements. An unprivileged user on a local network could use IPv6 Neighbor Discovery ICMP to broadcast a non-route with a low hop limit, causing machines to lower the hop limit on existing IPv6 routes. If this limit is small enough, IPv6 packets would be dropped before reaching the final destination.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5NetworkManagerNot affected
Red Hat Enterprise Linux 6NetworkManagerNot affected
Red Hat Enterprise Linux 7ModemManagerFixedRHSA-2015:231519.11.2015
Red Hat Enterprise Linux 7NetworkManagerFixedRHSA-2015:231519.11.2015
Red Hat Enterprise Linux 7network-manager-appletFixedRHSA-2015:231519.11.2015
Red Hat Enterprise Linux 7NetworkManager-libreswanFixedRHSA-2015:231519.11.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1209902NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

nvd
почти 10 лет назад

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

debian
почти 10 лет назад

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Disco ...

github
больше 3 лет назад

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

oracle-oval
почти 10 лет назад

ELSA-2015-2315: NetworkManager security, bug fix, and enhancement update (MODERATE)

3.3 Low

CVSS2