6.9
CVSSv2

CVE-2006-0038

Published: 22/03/2006 Updated: 13/02/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the do_replace function in netfilter for Linux prior to 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.11

linux linux kernel 2.6.12

linux linux kernel 2.6.14

linux linux kernel 2.6.5

linux linux kernel 2.6.15.3

linux linux kernel 2.6.1

linux linux kernel 2.6.16

linux linux kernel 2.6.13

linux linux kernel 2.6.13.3

linux linux kernel 2.6.11.8

linux linux kernel 2.6.14.4

linux linux kernel 2.6.10

linux linux kernel 2.6.14.3

linux linux kernel 2.6.11.6

linux linux kernel 2.6.11.11

linux linux kernel 2.6.0

linux linux kernel 2.6.3

linux linux kernel 2.6.4

linux linux kernel 2.6_test9_cvs

linux linux kernel 2.6.15.1

linux linux kernel 2.6.11.5

linux linux kernel 2.6.7

linux linux kernel 2.6.2

linux linux kernel 2.6.14.5

linux linux kernel 2.6.13.2

linux linux kernel 2.6.8

linux linux kernel 2.6.15

linux linux kernel 2.6.14.1

linux linux kernel 2.6.12.5

linux linux kernel 2.6.12.1

linux linux kernel 2.6.13.4

linux linux kernel 2.6.12.2

linux linux kernel 2.6.15.2

linux linux kernel 2.6.12.4

linux linux kernel 2.6.12.3

linux linux kernel 2.6.15.4

linux linux kernel 2.6.6

linux linux kernel 2.6.9

linux linux kernel 2.6.12.6

linux linux kernel 2.6.11.7

linux linux kernel 2.6.14.2

linux linux kernel 2.6.11.12

linux linux kernel 2.6.15.5

linux linux kernel 2.6.13.1

Vendor Advisories

An integer overflow was discovered in the do_replace() function A local user process with the CAP_NET_ADMIN capability could exploit this to execute arbitrary commands with full root privileges However, none of Ubuntu’s supported packages use this capability with any non-root user, so this only affects you if you use some third party software l ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3359 Franz Filz discovered that some socket calls permit causing inconsistent reference count ...