Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-2189
HistoryOct 10, 2011 - 12:00 a.m.

CVE-2011-2189

2011-10-1000:00:00
ubuntu.com
ubuntu.com
18

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.025

Percentile

90.2%

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not
properly handle a high rate of creation and cleanup of network namespaces,
which makes it easier for remote attackers to cause a denial of service
(memory consumption) via requests to a daemon that requires a separate
namespace per connection, as demonstrated by vsftpd.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchvsftpd< 2.2.2-3ubuntu6.3UNKNOWN
ubuntu10.10noarchvsftpd< 2.3.0~pre2-4ubuntu2.3UNKNOWN
ubuntu11.04noarchvsftpd< 2.3.2-3ubuntu4.1UNKNOWN
ubuntu11.10noarchvsftpd< 2.3.2-3ubuntu5.1UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.025

Percentile

90.2%