PT-2012-1528 · Linux+1 · Linux Kernel+1

Dan Rosenberg

·

Published

2012-06-21

·

Updated

2023-02-13

·

CVE-2011-1493

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.39
Description The issue is related to an array index error in the rose parse national function, which can be exploited by remote attackers to cause a denial of service or potentially have other unspecified impacts. This is achieved by composing FAC NATIONAL DIGIS data with a large number of digipeaters and sending it to a ROSE socket.
Recommendations For Linux kernel versions prior to 2.6.39, update to version 2.6.39 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2011-1493
DSA-2240-1
DSA-2264-1

Affected Products

Linux Kernel
Suse