Lucene search

K
cve[email protected]CVE-2014-2523
HistoryMar 24, 2014 - 4:40 p.m.

CVE-2014-2523

2014-03-2416:40:48
CWE-20
web.nvd.nist.gov
136
cve
2014
2523
linux kernel
denial of service
execute arbitrary code
dccp packet
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.075 Low

EPSS

Percentile

94.1%

net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a DCCP packet that triggers a call to the (1) dccp_new, (2) dccp_packet, or (3) dccp_error function.

Affected configurations

NVD
Node
linuxlinux_kernelRange<3.2.57
OR
linuxlinux_kernelRange3.33.4.86
OR
linuxlinux_kernelRange3.53.10.36
OR
linuxlinux_kernelRange3.113.12.17
OR
linuxlinux_kernelRange3.13.03.13.9
Node
canonicalubuntu_linuxMatch10.04-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

High

0.075 Low

EPSS

Percentile

94.1%