Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lin Ming

#40541de 53,632
6.6CVSS total
Vulnerabilidades · 1
PT-2013-2222
6.6
2013-02-20
Linux · Linux Kernel · CVE-2013-0310
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 3.4.8 **Description** The issue allows local users to cause a denial of service, resulting in a system crash due to a NULL pointer dereference. This is achieved through an IPOPT CIPSO IP OPTIONS setsockopt system call. The `cipso v4 validate` function in `net/ipv4/cipso ipv4.c` is the vulnerable component. **Recommendations** For Linux kernel versions prior to 3.4.8, update to version 3.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the `setsockopt` system call to minimize the risk of exploitation.