Oval Definition:oval:com.ubuntu.precise:def:20112213000
Revision Date:2011-08-29Version:1
Title:CVE-2011-2213 on Ubuntu 12.04 LTS (precise) - low.
Description:The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880. Dan Rosenberg discovered that the IPv4 diagnostic routines did not correctly validate certain requests. A local attacker could exploit this to consume CPU resources, leading to a denial of service.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2011-2213
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'linux' package in precise is not affected (note: '3.1.0-1.1').
  • OR NOT While related to the CVE in some way, the 'linux-ti-omap4' package in precise is not affected (note: '3.0.0-1401.2').
  • BACK