7.8

CVE-2011-2534

Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.39
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.365
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39
Vendor Advisory
Release Notes
http://www.openwall.com/lists/oss-security/2011/03/18/15
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2011/03/21/1
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2011/03/21/4
Patch
Third Party Advisory
Mailing List
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=961ed183a9fd080cf306c659b8736007e44065a5
http://marc.info/?l=netfilter&m=129978077509888&w=2
Patch
Third Party Advisory
http://marc.info/?l=netfilter-devel&m=130036157327564&w=2
Patch
Third Party Advisory
http://securityreason.com/securityalert/8284
Third Party Advisory
http://www.securityfocus.com/bid/46921
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=689337
Patch
Third Party Advisory
Issue Tracking