[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-4125Date: (C)2013-08-21   (M)2024-04-17


The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an ECMP route set until a change occurred for one of the first two routes, which allows remote attackers to cause a denial of service (system crash) via a crafted sequence of messages.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.4
Exploit Score: 4.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
SECTRACK-1028780
BID-61166
FEDORA-2013-13536
FEDORA-2013-13663
http://www.openwall.com/lists/oss-security/2013/07/15/4
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=307f2fb95e9b96b3577916e73d92e104f8f26494
https://bugzilla.redhat.com/show_bug.cgi?id=984664
https://github.com/torvalds/linux/commit/307f2fb95e9b96b3577916e73d92e104f8f26494
linux-cve20134125-dos(85645)

CWE    1
CWE-399
OVAL    42
oval:org.secpod.oval:def:1502923
oval:org.secpod.oval:def:1502921
oval:org.secpod.oval:def:106100
oval:org.secpod.oval:def:106120
...

© SecPod Technologies