Vulnerability Name: | CVE-2006-0039 (CCN-26583) | ||||||||||||||||||||
Assigned: | 2005-12-20 | ||||||||||||||||||||
Published: | 2006-05-16 | ||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||
Summary: | Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE. | ||||||||||||||||||||
CVSS v3 Severity: | 2.2 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.7 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:C)
| ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: CCN Type: Gentoo Bugzilla Bug 133465 Kernel: netfilter do_add_counters race (CVE-2006-0039) Source: secalert@redhat.com Type: Patch secalert@redhat.com Source: MITRE Type: CNA CVE-2006-0039 Source: CCN Type: The Linux Kernel Archives Web site The Linux Kernel Archives Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: RHSA-2006-0689 kernel security update Source: CCN Type: SA20185 Linux Kernel Netfilter Weakness and Two SCTP Vulnerabilities Source: CCN Type: SA21476 Linux Kernel Multiple Vulnerabilities Source: CCN Type: SA22945 Avaya Products Linux Kernel Multiple Vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: ASA-2006-249 kernel security update (RHSA-2006-0689) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: DEBIAN Type: DSA-1097 kernel-source-2.4.27 -- several vulnerabilities Source: DEBIAN Type: DSA-1103 kernel-source-2.6.8 -- several vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: OSVDB ID: 25697 Linux Kernel Netfilter do_add_counters() Function Local Memory Disclosure Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-18113 Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: TLSA-2007-2 Two vulnerabilities discovered in kernel Source: CCN Type: USN-311-1 Linux kernel vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Red Hat Bugzilla Bug 191698 CVE-2006-0039 netfilter do_add_counters race Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN linux-doaddcounters-race-condition(26583) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com | ||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |