PT-2012-1148 · Intel · Connman

Sebastian Krahmer

·

Publicado

2012-05-15

·

Atualizado

2017-08-29

·

CVE-2012-2322

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ConnMan versions prior to 1.0 ConnMan versions prior to 0.85
Description The issue is related to an integer overflow in the dhcpv6 get option function, which can cause a denial of service due to an infinite loop and crash. This can be triggered by remote attackers sending an invalid length value in a DHCP packet. Additionally, there are multiple vulnerabilities in the ConnMan package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For versions prior to 0.85, update to version 0.85 or later to resolve the integer overflow issue. For versions prior to 1.0, update to version 1.0 or later to address the multiple vulnerabilities. As a temporary workaround, consider restricting access to the dhcpv6 get option function until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09670
CVE-2012-2322

Produtos afetados

Connman