Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2844

Опубликовано: 18 авг. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.8

Описание

cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.31-6.25
hardy

not-affected

intrepid

not-affected

jaunty

not-affected

upstream

released

2.6.31

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

upstream

not-affected

Показывать по

Ссылки на источники

EPSS

Процентиль: 82%
0.01735
Низкий

7.8 High

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.

debian
больше 16 лет назад

cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and oth ...

github
больше 3 лет назад

cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.

EPSS

Процентиль: 82%
0.01735
Низкий

7.8 High

CVSS2