PT-2012-1994 · Linux+1 · Linux Kernel+1

Dan Rosenberg

·

Published

2012-06-21

·

Updated

2023-02-13

·

CVE-2011-4913

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.39
Description The issue is related to the rose parse ccitt function in the Linux kernel, which does not validate certain fields. This allows remote attackers to cause a denial of service or conduct stack-based buffer overflow attacks via specially crafted data sent to a ROSE socket.
Recommendations For Linux kernel versions prior to 2.6.39, update to version 2.6.39 or later to resolve the issue.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2011-4913
DSA-2240-1
DSA-2264-1

Affected Products

Linux Kernel
Suse