Lucene search

K
cve[email protected]CVE-2011-4913
HistoryJun 21, 2012 - 11:55 p.m.

CVE-2011-4913

2012-06-2123:55:02
CWE-20
web.nvd.nist.gov
48
8
cve
linux kernel
rose_parse_ccitt
vulnerability
nvd
denial of service
buffer overflow
remote attack

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

8.1 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.7%

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

Affected configurations

NVD
Node
novellsuse_linux_enterprise_serverMatch10.0sp4ltss
Node
linuxlinux_kernelRange2.6.38.8
OR
linuxlinux_kernelMatch2.6.38
OR
linuxlinux_kernelMatch2.6.38rc1
OR
linuxlinux_kernelMatch2.6.38rc2
OR
linuxlinux_kernelMatch2.6.38rc3
OR
linuxlinux_kernelMatch2.6.38rc4
OR
linuxlinux_kernelMatch2.6.38rc5
OR
linuxlinux_kernelMatch2.6.38rc6
OR
linuxlinux_kernelMatch2.6.38rc7
OR
linuxlinux_kernelMatch2.6.38rc8
OR
linuxlinux_kernelMatch2.6.38.1
OR
linuxlinux_kernelMatch2.6.38.2
OR
linuxlinux_kernelMatch2.6.38.3
OR
linuxlinux_kernelMatch2.6.38.4
OR
linuxlinux_kernelMatch2.6.38.5
OR
linuxlinux_kernelMatch2.6.38.6
OR
linuxlinux_kernelMatch2.6.38.7

Social References

More

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

8.1 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.7%