Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4125
HistoryJul 15, 2013 - 12:00 a.m.

CVE-2013-4125

2013-07-1500:00:00
ubuntu.com
ubuntu.com
12

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

0.046 Low

EPSS

Percentile

92.6%

The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in
the Linux kernel through 3.10.1 does not properly handle Router
Advertisement (RA) messages in certain circumstances involving three routes
that initially qualified for membership in an ECMP route set until a change
occurred for one of the first two routes, which allows remote attackers to
cause a denial of service (system crash) via a crafted sequence of
messages.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu13.04noarchlinux< 3.8.0-29.42UNKNOWN
ubuntu12.04noarchlinux-lts-raring< 3.8.0-29.42~precise1UNKNOWN

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

0.046 Low

EPSS

Percentile

92.6%