Lucene search

K
cve[email protected]CVE-2015-4004
HistoryJun 07, 2015 - 11:59 p.m.

CVE-2015-4004

2015-06-0723:59:08
CWE-119
web.nvd.nist.gov
64
cve-2015-4004
ozwpan
linux kernel
packet parsing
denial of service
out-of-bounds read
system crash
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:N/A:C

AI Score

7.7

Confidence

High

EPSS

0.028

Percentile

90.7%

The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.

Affected configurations

NVD
Node
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch14.04esm
OR
canonicalubuntu_linuxMatch15.10
Node
linuxlinux_kernelRange3.44.3
VendorProductVersionCPE
canonicalubuntu_linux12.04cpe:/o:canonical:ubuntu_linux:12.04::-:
canonicalubuntu_linux15.10cpe:/o:canonical:ubuntu_linux:15.10:::
canonicalubuntu_linux14.04cpe:/o:canonical:ubuntu_linux:14.04::esm:

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:N/A:C

AI Score

7.7

Confidence

High

EPSS

0.028

Percentile

90.7%