Revision Date: | 2013-12-09 | Version: | 1 | Title: | CVE-2013-6431 on Ubuntu 12.04 LTS (precise) - medium. | Description: | The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for an IPv6 SIOCADDRT ioctl call. A flaw was discovered in the Linux kernel's fib6 error-code encoding for IPv6. A local user with the CAT_NET_ADMIN capability could exploit this flaw to cause a denial of service (system crash).
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2013-6431
| Platform(s): | Ubuntu 12.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 12.04 LTS (precise) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in precise is not affected.
OR NOT While related to the CVE in some way, the 'linux-armadaxp' package in precise is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-lts-quantal' package in precise is not affected.
OR The 'linux-lts-raring' package in precise was vulnerable but has been fixed (note: '3.8.0-34.49~precise1').
OR NOT While related to the CVE in some way, the 'linux-lts-saucy' package in precise is not affected (note: '3.11.0-13.20~precise2').
OR NOT While related to the CVE in some way, the 'linux-lts-trusty' package in precise is not affected (note: '3.13.0-24.46~precise1').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-ti-omap4' package in precise is not affected.
|
|