PT-2011-1066 · Suse+2 · Ext4Dev-Kmp-Trace+2
Dan Kaminsky
·
Publicado
2011-08-31
·
Atualizado
2023-02-13
·
CVE-2011-3188
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.1
ext4dev-kmp-trace (affected versions not specified)
Description
The issue concerns the Linux kernel's IPv4 and IPv6 implementations, which use a modified MD4 algorithm. This makes it easier for remote attackers to disrupt networking or hijack network sessions by predicting sequence numbers and Fragment Identification values and sending crafted packets. Additionally, multiple vulnerabilities in the ext4dev-kmp-trace package of SUSE Linux Enterprise may lead to a disruption of protected information availability, exploitable remotely.
Recommendations
For Linux kernel versions prior to 3.1, update to version 3.1 or later to resolve the issue.
For ext4dev-kmp-trace, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Ext4Dev-Kmp-Trace