PT-2003-1002 · Iproute · Iproute

Publicado

2003-11-18

·

Atualizado

2017-10-11

·

CVE-2003-0856

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions iproute versions 2.4.7 and earlier
Description The issue affects the iproute package, allowing local users to cause a denial of service via spoofed messages to the kernel netlink interface. This can lead to a disruption in the availability of protected information. The exploitation can be carried out locally.
Recommendations For iproute versions 2.4.7 and earlier, consider restricting access to the kernel netlink interface as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01286
BDU:2015-07763
CVE-2003-0856
DSA-492
RHSA-2003:317

Produtos afetados

Iproute