[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-3809Date: (C)2005-11-25   (M)2023-12-22


The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.8
Exploit Score: 10.0
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
OSVDB-24114
http://marc.info/?l=linux-kernel&m=113269476105016&w=2
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.14.3

CPE    8
cpe:/o:linux:linux_kernel:2.6.14:rc2
cpe:/o:linux:linux_kernel:2.6.14:rc3
cpe:/o:linux:linux_kernel:2.6.14:rc1
cpe:/o:linux:linux_kernel:2.6.14
...

© SecPod Technologies