5
CVE-2014-8160
- EPSS 5.49%
- Veröffentlicht 02.03.2015 11:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.18
Suse ≫ Linux Enterprise Desktop Version 12
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update -
Suse ≫ Linux Enterprise Workstation Extension Version 12
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 6.5
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 6.5
Redhat ≫ Enterprise Linux Server Eus Version 6.6
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 6.5
Redhat ≫ Enterprise Linux Server Tus Version 6.6
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.49% | 0.918 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html
http://rhn.redhat.com/errata/RHSA-2015-0284.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
http://rhn.redhat.com/errata/RHSA-2015-0290.html
http://www.ubuntu.com/usn/USN-2513-1
http://www.ubuntu.com/usn/USN-2514-1
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
http://rhn.redhat.com/errata/RHSA-2015-0674.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html
http://www.debian.org/security/2015/dsa-3170
http://www.ubuntu.com/usn/USN-2515-1
http://www.ubuntu.com/usn/USN-2516-1
http://www.ubuntu.com/usn/USN-2517-1
http://www.ubuntu.com/usn/USN-2518-1
http://www.mandriva.com/security/advisories?name=MDVSA-2015:057
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=db29a9508a9246e77087c5531e45b2c88ec6988b
http://www.openwall.com/lists/oss-security/2015/01/14/3
http://www.securityfocus.com/bid/72061
http://www.spinics.net/lists/netfilter-devel/msg33430.html
https://bugzilla.redhat.com/show_bug.cgi?id=1182059
https://github.com/torvalds/linux/commit/db29a9508a9246e77087c5531e45b2c88ec6988b