Oval Definition:oval:com.ubuntu.precise:def:20141690000
Revision Date:2014-02-28Version:1
Title:CVE-2014-1690 on Ubuntu 12.04 LTS (precise) - low.
Description:The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature. An information leak was discovered in the Linux kernel when built with the NetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol (NF_NAT_IRC). A remote attacker could exploit this flaw to obtain potentially sensitive kernel information when communicating over a client- to-client IRC connection(/dcc) via a NAT-ed network.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-1690
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'linux' package in precise is not affected.
  • OR NOT While related to the CVE in some way, the 'linux-armadaxp' package in precise is not affected.
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR NOT While related to the CVE in some way, the 'linux-lts-quantal' package in precise is not affected.
  • OR The 'linux-lts-raring' package in precise was vulnerable but has been fixed (note: '3.8.0-38.56~precise1').
  • OR The 'linux-lts-saucy' package in precise was vulnerable but has been fixed (note: '3.11.0-18.32~precise1').
  • OR NOT While related to the CVE in some way, the 'linux-lts-trusty' package in precise is not affected (note: '3.13.0-24.46~precise1').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR NOT While related to the CVE in some way, the 'linux-ti-omap4' package in precise is not affected.
  • BACK