[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80130

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-5970

Date: (C)2017-02-16   (M)2018-01-05 


The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.

CVSS Score: 5.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL





Reference:
BID-96233
DSA-3791
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017:2669
http://www.openwall.com/lists/oss-security/2017/02/12/3
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=34b2cef20f19c87999fff3da4071e66937db9644
https://bugzilla.redhat.com/show_bug.cgi?id=1421638
https://github.com/torvalds/linux/commit/34b2cef20f19c87999fff3da4071e66937db9644
https://patchwork.ozlabs.org/patch/724136/
https://source.android.com/security/bulletin/2017-07-01

CWE    1
CWE-284
OVAL    12
oval:org.secpod.oval:def:1501819
oval:org.secpod.oval:def:1501817
oval:org.secpod.oval:def:1501822
oval:org.secpod.oval:def:1501820
...

© 2013 SecPod Technologies