7.1

CVE-2013-4348

Exploit

The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.2 < 3.2.54
LinuxLinux Kernel Version >= 3.3 < 3.4.70
LinuxLinux Kernel Version >= 3.5 < 3.10.20
LinuxLinux Kernel Version >= 3.11 < 3.11.9
LinuxLinux Kernel Version >= 3.12 < 3.12.1
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version13.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.27% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C