Vulnerability Name: CVE-2006-0454 (CCN-24575) Assigned: 2006-02-07 Published: 2006-02-07 Updated: 2018-10-19 Summary: Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2006-0454 Source: MLIST Type: Patch[dailydave] 20060207 Fun with Linux (2.6.12 -> 2.6.15.2) Source: MLIST Type: UNKNOWN[linux-kernel] 20060207 Linux 2.6.15.3 Source: MLIST Type: UNKNOWN[linux-kernel] 20060207 Re: Linux 2.6.15.3 Source: CCN Type: linux-kernel Mailing List, 2006-02-07 1:41:22Linux 2.6.15.3 Source: CCN Type: SA18766Linux Kernel ICMP Error Handling Denial of Service Source: SECUNIA Type: Patch, Vendor Advisory18766 Source: SECUNIA Type: Patch, Vendor Advisory18774 Source: SECUNIA Type: Patch, Vendor Advisory18784 Source: SECUNIA Type: Patch, Vendor Advisory18788 Source: SECUNIA Type: Patch, Vendor Advisory18861 Source: CCN Type: The The Linux Kernel Archives Web siteThe Linux Kernel Archives Source: CCN Type: The Linux Kernel Archives Web siteChangeLog-2.6.15.3 Source: CONFIRM Type: UNKNOWNhttp://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3 Source: MANDRIVA Type: UNKNOWNMDKSA-2006:040 Source: SUSE Type: Patch, Vendor AdvisorySUSE-SA:2006:006 Source: CCN Type: OSVDB ID: 22993Linux Kernel ip_options_echo() Function Crafted ICMP Packet Remote DoS Source: FEDORA Type: Patch, Vendor AdvisoryFEDORA-2006-102 Source: FEDORA Type: UNKNOWNFLSA:157459-4 Source: BID Type: Patch16532 Source: CCN Type: BID-16532Linux Kernel ICMP_Send Remote Denial Of Service Vulnerability Source: TRUSTIX Type: Vendor Advisory2006-0006 Source: CCN Type: USN-250-1linux-source-2.6.12 vulnerability Source: UBUNTU Type: UNKNOWNUSN-250-1 Source: VUPEN Type: Vendor AdvisoryADV-2006-0464 Source: XF Type: UNKNOWNkernel-icmp-ipoptionsecho-dos(24575) Source: XF Type: UNKNOWNkernel-icmp-ipoptionsecho-dos(24575) Source: SUSE Type: SUSE-SA:2006:006kernel remote denial of service attack Vulnerable Configuration: Configuration 1 :cpe:/o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc6:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc2:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc3:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc5:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc5:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.15:rc2:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13:-:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:* OR cpe:/o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:* AND cpe:/o:suse:suse_linux:9.2:*:*:*:*:*:*:* OR cpe:/o:suse:suse_linux:10.0::oss:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2006:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2006::x86-64:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
linux linux kernel 2.6.12
linux linux kernel 2.6.12 rc1
linux linux kernel 2.6.12 rc2
linux linux kernel 2.6.12 rc3
linux linux kernel 2.6.12 rc4
linux linux kernel 2.6.12 rc5
linux linux kernel 2.6.12 rc6
linux linux kernel 2.6.12.1
linux linux kernel 2.6.12.2
linux linux kernel 2.6.12.3
linux linux kernel 2.6.12.4
linux linux kernel 2.6.12.5
linux linux kernel 2.6.12.6
linux linux kernel 2.6.13
linux linux kernel 2.6.13 rc1
linux linux kernel 2.6.13 rc2
linux linux kernel 2.6.13 rc3
linux linux kernel 2.6.13 rc4
linux linux kernel 2.6.13 rc5
linux linux kernel 2.6.13 rc6
linux linux kernel 2.6.13 rc7
linux linux kernel 2.6.13.1
linux linux kernel 2.6.13.2
linux linux kernel 2.6.13.3
linux linux kernel 2.6.13.4
linux linux kernel 2.6.13.5
linux linux kernel 2.6.14
linux linux kernel 2.6.14 rc1
linux linux kernel 2.6.14 rc2
linux linux kernel 2.6.14 rc3
linux linux kernel 2.6.14 rc4
linux linux kernel 2.6.14 rc5
linux linux kernel 2.6.14.1
linux linux kernel 2.6.14.2
linux linux kernel 2.6.14.3
linux linux kernel 2.6.14.4
linux linux kernel 2.6.14.5
linux linux kernel 2.6.14.6
linux linux kernel 2.6.14.7
linux linux kernel 2.6.15
linux linux kernel 2.6.15.1
linux linux kernel 2.6.15.2
linux linux kernel 2.6.14.4
linux linux kernel 2.6.14.3
linux linux kernel 2.6.15.1
linux linux kernel 2.6.15
linux linux kernel 2.6.14
linux linux kernel 2.6.15 rc7
linux linux kernel 2.6.15 rc6
linux linux kernel 2.6.15 rc5
linux linux kernel 2.6.15 rc4
linux linux kernel 2.6.15 rc3
linux linux kernel 2.6.14 rc2
linux linux kernel 2.6.15 rc1
linux linux kernel 2.6.15.3
linux linux kernel 2.6.15.2
linux linux kernel 2.6.15 rc2
linux linux kernel 2.6.14 rc4
linux linux kernel 2.6.14 rc3
linux linux kernel 2.6.14 rc1
linux linux kernel 2.6.14.2
linux linux kernel 2.6.14.1
linux linux kernel 2.6.13 rc7
linux linux kernel 2.6.13 rc6
linux linux kernel 2.6.13 rc4
linux linux kernel 2.6.13 rc1
linux linux kernel 2.6.12 rc5
linux linux kernel 2.6.12 rc4
linux linux kernel 2.6.12 rc1
linux linux kernel 2.6.12
linux linux kernel 2.6.12.1
linux linux kernel 2.6.12.2
linux linux kernel 2.6.12.3
linux linux kernel 2.6.12.4
linux linux kernel 2.6.12.5
linux linux kernel 2.6.12.6
linux linux kernel 2.6.13
linux linux kernel 2.6.13.1
linux linux kernel 2.6.13.2
linux linux kernel 2.6.13.3
linux linux kernel 2.6.13.4
suse suse linux 9.2
suse suse linux 10.0
mandrakesoft mandrake linux 2006
mandrakesoft mandrake linux 2006