7.8

CVE-2009-4536

drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.32.3
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.59% 0.806
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
http://marc.info/?t=126203102000001&r=1&w=2
Third Party Advisory
Mailing List
http://securitytracker.com/id?1023420
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/37519
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=552126
Third Party Advisory
Issue Tracking