PT-2017-17707 · Blackbox · Backbox Linux

Hosein Askari

·

Published

2017-04-03

·

Updated

2024-08-05

·

CVE-2017-7397

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BackBox Linux version 4.6
Description The issue allows remote attackers to cause a denial of service, specifically ksoftirqd CPU consumption, via a flood of packets with Martian source IP addresses, as defined in RFC 1812 section 5.3.7. This product enables net.ipv4.conf.all.log martians by default. However, the vendor reports that this vulnerability has no foundation and is totally fake and based on false assumptions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2017-7397

Affected Products

Backbox Linux