Lucene search

K
cveRedhatCVE-2011-1927
HistoryJun 13, 2012 - 10:24 a.m.

CVE-2011-1927

2012-06-1310:24:54
redhat
web.nvd.nist.gov
57
2
cve-2011-1927
linux kernel
denial of service
ip_expire
icmp_time_exceeded

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.6

Confidence

High

EPSS

0.007

Percentile

81.1%

The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.

Affected configurations

Nvd
Node
linuxlinux_kernelRange2.6.38.8
OR
linuxlinux_kernelMatch2.6.38
OR
linuxlinux_kernelMatch2.6.38rc1
OR
linuxlinux_kernelMatch2.6.38rc2
OR
linuxlinux_kernelMatch2.6.38rc3
OR
linuxlinux_kernelMatch2.6.38rc4
OR
linuxlinux_kernelMatch2.6.38rc5
OR
linuxlinux_kernelMatch2.6.38rc6
OR
linuxlinux_kernelMatch2.6.38rc7
OR
linuxlinux_kernelMatch2.6.38rc8
OR
linuxlinux_kernelMatch2.6.38.1
OR
linuxlinux_kernelMatch2.6.38.2
OR
linuxlinux_kernelMatch2.6.38.3
OR
linuxlinux_kernelMatch2.6.38.4
OR
linuxlinux_kernelMatch2.6.38.5
OR
linuxlinux_kernelMatch2.6.38.6
OR
linuxlinux_kernelMatch2.6.38.7
VendorProductVersionCPE
linuxlinux_kernel2.6.38.5cpe:/o:linux:linux_kernel:2.6.38.5:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc5::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc8::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc3::
linuxlinux_kernel2.6.38.2cpe:/o:linux:linux_kernel:2.6.38.2:::
linuxlinux_kernel2.6.38.6cpe:/o:linux:linux_kernel:2.6.38.6:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:::
linuxlinux_kernel2.6.38.7cpe:/o:linux:linux_kernel:2.6.38.7:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc7::
linuxlinux_kernel2.6.38.4cpe:/o:linux:linux_kernel:2.6.38.4:::
Rows per page:
1-10 of 171

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.6

Confidence

High

EPSS

0.007

Percentile

81.1%