7.1

CVE-2014-6418

Exploit

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 3.2.64
LinuxLinux Kernel Version >= 3.3 < 3.4.105
LinuxLinux Kernel Version >= 3.5 < 3.10.55
LinuxLinux Kernel Version >= 3.11 < 3.12.29
LinuxLinux Kernel Version >= 3.13 < 3.14.19
LinuxLinux Kernel Version >= 3.15 < 3.16.3
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.97% 0.88
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C