CVE-2005-4886

HIGH

Description

The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d3d077cd4f1154e63a9858e47fe3fb1ad0c03e5

http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.12/ChangeLog-2.6.12-rc4

http://www.openwall.com/lists/oss-security/2010/02/22/3

https://bugzilla.redhat.com/show_bug.cgi?id=160117

https://exchange.xforce.ibmcloud.com/vulnerabilities/56614

Details

Source: MITRE

Published: 2010-02-26

Updated: 2018-10-30

Type: CWE-189

Risk Information

CVSS v2.0

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH