Lucene search

K
cve[email protected]CVE-2011-4326
HistoryMay 17, 2012 - 11:00 a.m.

CVE-2011-4326

2012-05-1711:00:33
CWE-399
web.nvd.nist.gov
48
8
cve-2011-4326
udp6_ufo_fragment
net/ipv6/udp.c
linux kernel
denial of service
system crash
nvd

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

5.7 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.3%

The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.

Affected configurations

NVD
Node
linuxlinux_kernelRange<2.6.39
Node
avaya96x1_ip_deskphone_firmwareRange6.0.06.6.0
AND
avaya96x1_ip_deskphoneMatch-

Social References

More

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

5.7 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.3%