VulDB: Linux Kernel net/ipv6/netfilter/nf_conntrack_reasm.c nf_ct_frag6_reasm() denial of service
General

scipID: 5655
Affected: Linux Kernel
Published: 07/10/2012
Risk:
problematic
Entry: 85.3% complete
Created: 07/19/2012
Updated: 09/03/2012
Summary
A vulnerability, which was classified as problematic, was found in Linux Kernel. This affects the function nf_ct_frag6_reasm() of the file _net/ipv6/netfilter/nf_conntrack_reasm.c_. The manipulation with an unknown input leads to a denial of service vulnerability. This is going to have an impact on availability.
The weakness was published 07/10/2012 with Beyond Security’s SecuriTeam Secure Disclosure as RHSA-2012:1064-2 as advisory (Red Hat Security Advisory). The advisory is shared for download at rhn.redhat.com. This vulnerability is uniquely identified as CVE-2012-2744 since 05/14/2012. It is possible to initiate the attack remotely. No form of authentication is needed for exploitation. Technical details of the vulnerability are known, but there is no available exploit.
The best possible mitigation is suggested to be patching the affected component. A possible mitigation has been published immediately after the disclosure of the vulnerability. The vulnerability is also documented in the databases at OSVDB (83665) and Secunia (SA49778).CVSS
Base Score: 7.1 (CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C) [?]
| Access Vector | Access Complexity | Authentication | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|
| Local | High | Multiple | None | None | None |
| Adjacent | Medium | Single | Partial | Partial | Partial |
| Network | Low | None | Complete | Complete | Complete |
Exploiting
Class: Denial of service
Local: No
Remote: Yes
Availability: No
Countermeasures
Recommended: Patch
Reaction Time: 0 days since reported
0-Day Time: 0 days since found
Exposure Time: 0 days since known
Timeline
05/14/2012 | CVE assigned
07/10/2012 | Advisory disclosed
07/10/2012 | Countermeasure disclosed
07/10/2012 | OSVDB entry created
07/19/2012 | VulDB entry created
09/03/2012 | VulDB entry updated
Sources
Advisory: RHSA-2012:1064-2
Company: Beyond Security’s SecuriTeam Secure Disclosure
OSVDB: 83665
CVE: CVE-2012-2744 (mitre.org) (nist.org) (cvedetails.com)
Secunia: 49778



















