Lucene search

K
cve[email protected]CVE-2010-4160
HistoryJan 07, 2011 - 12:00 p.m.

CVE-2010-4160

2011-01-0712:00:48
CWE-190
web.nvd.nist.gov
72
8
cve-2010-4160
integer overflows
linux kernel
pppol2tp_sendmsg
l2tp_ip_sendmsg
denial of service
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.

Affected configurations

NVD
Node
linuxlinux_kernelRange<2.6.36.2
Node
opensuseopensuseMatch11.2
OR
suselinux_enterprise_desktopMatch10sp3
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp3
OR
suselinux_enterprise_serverMatch11sp1
OR
suselinux_enterprise_software_development_kitMatch10sp3

References

Social References

More

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%