Back to search
CVE-2011-3188
Published: May 24, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20110823 Re: CVE request: kernel: change in how tcp seq numbers are generated
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=732658
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1
x_refsource_CONFIRM
HPSBGN02970
vendor-advisory
x_refsource_HP
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now