Vulnerability Name:

CVE-2011-3347 (CCN-70884)

Assigned:2011-10-20
Published:2011-10-20
Updated:2023-02-13
Summary:A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:A/AC:H/Au:N/C:N/I:N/A:C)
3.4 Low (Temporal CVSS v2 Vector: AV:A/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.6 Medium (REDHAT CVSS v2 Vector: AV:A/AC:H/Au:N/C:N/I:N/A:C)
3.4 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2011-3347

Source: CCN
Type: RHSA-2011-1386
Important: kernel security, bug fix, and enhancement update

Source: CCN
Type: RHSA-2011-1408
Moderate: rhev-hypervisor security update

Source: CCN
Type: RHSA-2011-1530
Moderate: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update

Source: CCN
Type: RHSA-2012-0116
Moderate: kernel security and bug fix update

Source: CCN
Type: OSVDB ID: 77571
Linux Kernel be2net VLAN Packet Parsing Remote DoS

Source: CCN
Type: BID-50312
Red Hat Linux Kernel CVE-2011-3347 VLAN Packets Handling Remote Denial of Service Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 736425
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
linux-kernel-vlan-dos(70884)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2011:1386-1
Important: kernel security, bug fix, and enhancement update

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:5::client:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:workstation:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_eus:6.1.z:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:enterprise_virtualization:2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:27801
    P
    ELSA-2011-1530 -- Oracle Linux 6 kernel security, bug fix and enhancement update (moderate)
    2014-12-15
    oval:org.mitre.oval:def:27217
    P
    RHSA-2011:1530 -- Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)
    2014-12-08
    oval:org.mitre.oval:def:17618
    P
    USN-1412-1 -- linux vulnerability
    2014-06-30
    oval:org.mitre.oval:def:14536
    P
    USN-1404-1 -- Linux kernel (OMAP4) vulnerability
    2014-06-30
    oval:org.mitre.oval:def:15418
    P
    USN-1409-1 -- Linux kernel (Oneiric backport) vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:23388
    P
    ELSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2014-05-26
    oval:org.mitre.oval:def:21885
    P
    RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2014-02-24
    oval:org.opensuse.security:def:20113347
    V
    CVE-2011-3347
    2013-08-14
    oval:com.ubuntu.xenial:def:20113347000
    V
    CVE-2011-3347 on Ubuntu 16.04 LTS (xenial) - low.
    2013-06-08
    oval:com.ubuntu.precise:def:20113347000
    V
    CVE-2011-3347 on Ubuntu 12.04 LTS (precise) - low.
    2013-06-08
    oval:com.ubuntu.xenial:def:201133470000000
    V
    CVE-2011-3347 on Ubuntu 16.04 LTS (xenial) - low.
    2013-06-08
    oval:com.ubuntu.trusty:def:20113347000
    V
    CVE-2011-3347 on Ubuntu 14.04 LTS (trusty) - low.
    2013-06-08
    oval:com.redhat.rhsa:def:20111530
    P
    RHSA-2011:1530: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)
    2011-12-06
    oval:com.redhat.rhsa:def:20111386
    P
    RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2011-10-20
    BACK
    redhat enterprise linux 5
    redhat enterprise linux desktop 5
    redhat enterprise linux 5
    redhat enterprise linux 6
    redhat enterprise linux 6
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise linux server eus 6.1.z
    redhat enterprise virtualization 2.2