Back to search
CVE-2012-3520
Published: Oct 3, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20120822 CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
mailing-list
x_refsource_MLIST
55152
vdb-entry
x_refsource_BID
openSUSE-SU-2012:1330
vendor-advisory
x_refsource_SUSE
USN-1599-1
vendor-advisory
x_refsource_UBUNTU
USN-1610-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2013:0261
vendor-advisory
x_refsource_SUSE
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.30
x_refsource_CONFIRM
50848
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=850449
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now