Vulnerability Name:

CVE-2011-3603 (CCN-70415)

Assigned:2011-10-07
Published:2011-10-07
Updated:2014-04-28
Summary:The router advertisement daemon (radvd) before 1.8.2 does not properly handle errors in the privsep_init function, which causes the radvd daemon to run as root and has an unspecified impact.
Per http://thread.gmane.org/gmane.comp.security.oss.general/5973/focus=6015, this vulnerablity is being assigned a CVSS base metric of AV:L/AC:M/Au:N/C:P/I:P/A:P = 4.4
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2011-3603

Source: CCN
Type: SA46200
radvd Privilege Escalation and Denial of Service Vulnerabilities

Source: CCN
Type: radvd Web Site
Linux IPv6 Router Advertisement Daemon (radvd)

Source: CONFIRM
Type: UNKNOWN
http://www.litech.org/radvd/CHANGES

Source: CCN
Type: oss-security:Solar Designer | 7 Oct 02:52
radvd 1.8.2 released with security fixes

Source: MLIST
Type: UNKNOWN
[oss-security] 20111007 radvd 1.8.2 released with security fixes

Source: CCN
Type: OSVDB ID: 76129
radvd privsep_init() Error Weakness Privilege Escalation

Source: CCN
Type: BID-50395
radvd Multiple Local and Remote Vulnerabilities

Source: MISC
Type: UNKNOWN
https://access.redhat.com/security/cve/CVE-2011-3603

Source: XF
Type: UNKNOWN
radvd-privsepinit-privilege-escalation(70415)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:litech:router_advertisement_daemon:*:*:*:*:*:*:*:* (Version <= 1.8.1)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20113603
    V
    CVE-2011-3603
    2022-05-20
    oval:org.opensuse.security:def:42433
    P
    Security update for vim (Important)
    2022-04-19
    oval:org.opensuse.security:def:31752
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:33117
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:31753
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:31370
    P
    Security update for java-1_7_1-ibm (Moderate) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:32246
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:26177
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:31710
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:31296
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:26152
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:32207
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:32206
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:31285
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:30257
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:26143
    P
    Security update for curl (Moderate)
    2021-10-11
    oval:org.opensuse.security:def:42224
    P
    Security update for curl (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:29432
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:26120
    P
    Security update for xerces-c (Important)
    2021-09-03
    oval:org.opensuse.security:def:26099
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:32158
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:31651
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:26085
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:30220
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:32950
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:32119
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:42693
    P
    radvd-1.1-1.24.8.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36286
    P
    radvd-1.1-1.24.8.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32104
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:32102
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:26046
    P
    Security update for libxml2 (Moderate)
    2021-05-05
    oval:org.opensuse.security:def:26039
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:33631
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:32062
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:32060
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:29481
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:26205
    P
    Security update for openssl-1_0_0 (Moderate)
    2021-03-08
    oval:org.opensuse.security:def:32268
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:31738
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:33022
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:31284
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:32989
    P
    Security update for cups (Moderate)
    2021-02-02
    oval:org.opensuse.security:def:29378
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:28867
    P
    Security update for openssl (Important)
    2020-12-11
    oval:org.opensuse.security:def:35817
    P
    radvd-1.1-1.24.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36026
    P
    radvd-1.1-1.24.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31999
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:32742
    P
    log4net on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31493
    P
    Security update for python
    2020-12-01
    oval:org.opensuse.security:def:31802
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32312
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:31970
    P
    Security update for ipsec-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32362
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32528
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32887
    P
    java-1_7_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33261
    P
    strongswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33563
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34309
    P
    Security update for radvd
    2020-12-01
    oval:org.opensuse.security:def:25443
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25793
    P
    Security update for icedtea-web (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26816
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25587
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25917
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:26254
    P
    Security update for dia (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26989
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25836
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26465
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26611
    P
    mailman on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28786
    P
    Security update for mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28998
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29538
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32038
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32781
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31504
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31859
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32418
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32572
    P
    libvorbis on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32796
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33418
    P
    Security update for NetworkManager
    2020-12-01
    oval:org.opensuse.security:def:33587
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25367
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25571
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25944
    P
    Security update for libplist (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25651
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:26001
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26293
    P
    Security update for raptor (Important)
    2020-12-01
    oval:org.opensuse.security:def:27024
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25847
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26514
    P
    LibVNCServer on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27249
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28787
    P
    Security update for Mozilla NSS
    2020-12-01
    oval:org.opensuse.security:def:29084
    P
    Security update for dnsmasq (Important)
    2020-12-01
    oval:org.opensuse.security:def:29582
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31502
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31894
    P
    Security update for fetchmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31578
    P
    Security update for supportutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31946
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31764
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLE and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:32467
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33210
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32797
    P
    tftp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33475
    P
    Security update for Mozilla
    2020-12-01
    oval:org.opensuse.security:def:25368
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25652
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25997
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25575
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25779
    P
    Security update for the SUSE Linux Enterprise 12 kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26307
    P
    Security update for conntrack-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25911
    P
    Security update for gstreamer-plugins-base (Low)
    2020-12-01
    oval:org.opensuse.security:def:26261
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26553
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27284
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28798
    P
    Security update for OpenSLP
    2020-12-01
    oval:org.opensuse.security:def:29141
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31594
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31950
    P
    Security update for grub2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31492
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:31838
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:32506
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33249
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32808
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33174
    P
    libproxy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33524
    P
    Security update for tar
    2020-12-01
    oval:org.opensuse.security:def:34269
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:25379
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25709
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26781
    P
    mailman on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25576
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25860
    P
    Security update for bash (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26351
    P
    Security update for mongodb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25835
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26412
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26567
    P
    java-1_4_2-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29225
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29520
    P
    Security update for LibVNCServer (Critical)
    2020-12-01
    BACK
    litech router advertisement daemon *