Back to search
CVE-2013-4163
Published: Jul 28, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-1943-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2013:1473
vendor-advisory
x_refsource_SUSE
USN-1938-1
vendor-advisory
x_refsource_UBUNTU
61412
vdb-entry
x_refsource_BID
USN-1944-1
vendor-advisory
x_refsource_UBUNTU
USN-1945-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2013:1474
vendor-advisory
x_refsource_SUSE
https://bugzilla.redhat.com/show_bug.cgi?id=987633
x_refsource_CONFIRM
USN-1947-1
vendor-advisory
x_refsource_UBUNTU
54148
third-party-advisory
x_refsource_SECUNIA
USN-1941-1
vendor-advisory
x_refsource_UBUNTU
USN-1942-1
vendor-advisory
x_refsource_UBUNTU
USN-1946-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now