5
CVSSv2

CVE-2006-1242

Published: 15/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ip_push_pending_frames function in Linux 2.4.x and 2.6.x prior to 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote malicious users to conduct an Idle Scan (nmap -sI) attack, which bypasses intended protections against such attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.4.0

linux linux kernel 2.4.1

linux linux kernel 2.4.10

linux linux kernel 2.4.17

linux linux kernel 2.4.18

linux linux kernel 2.4.19

linux linux kernel 2.4.2

linux linux kernel 2.4.23

linux linux kernel 2.4.27

linux linux kernel 2.4.3

linux linux kernel 2.4.30

linux linux kernel 2.4.15

linux linux kernel 2.4.16

linux linux kernel 2.4.21

linux linux kernel 2.4.22

linux linux kernel 2.4.26

linux linux kernel 2.4.29

linux linux kernel 2.4.32

linux linux kernel 2.4.8

linux linux kernel 2.4.9

linux linux kernel 2.4.11

linux linux kernel 2.4.12

linux linux kernel 2.4.20

linux linux kernel 2.4.23_ow2

linux linux kernel 2.4.24

linux linux kernel 2.4.4

linux linux kernel 2.4.5

linux linux kernel 2.6.0

linux linux kernel 2.6.1

linux linux kernel 2.6.11.12

linux linux kernel 2.6.11.5

linux linux kernel 2.6.12.2

linux linux kernel 2.6.12.3

linux linux kernel 2.6.13

linux linux kernel 2.6.13.1

linux linux kernel 2.6.14

linux linux kernel 2.4.13

linux linux kernel 2.4.14

linux linux kernel 2.4.24_ow1

linux linux kernel 2.4.25

linux linux kernel 2.4.28

linux linux kernel 2.4.31

linux linux kernel 2.4.6

linux linux kernel 2.4.7

linux linux kernel 2.6.11.6

linux linux kernel 2.6.11.7

linux linux kernel 2.6.12.4

linux linux kernel 2.6.12.5

linux linux kernel 2.6.13.2

linux linux kernel 2.6.13.3

linux linux kernel 2.6.14.1

linux linux kernel 2.6.14.2

linux linux kernel 2.6.15

linux linux kernel 2.6.15.1

linux linux kernel 2.6.2

linux linux kernel 2.6.3

linux linux kernel 2.6.8

linux linux kernel 2.6.7

linux linux kernel 2.6.10

linux linux kernel 2.6.11.8

linux linux kernel 2.6.11

linux linux kernel 2.6.12.6

linux linux kernel 2.6.12

linux linux kernel 2.6.13.4

linux linux kernel 2.6.14.3

linux linux kernel 2.6.14.4

linux linux kernel 2.6.14.5

linux linux kernel 2.6.15.2

linux linux kernel 2.6.15.3

linux linux kernel 2.6.4

linux linux kernel 2.6.5

linux linux kernel 2.6.9

linux linux kernel 2.4.33

linux linux kernel 2.6.11.11

linux linux kernel 2.6.12.1

linux linux kernel 2.6.15.4

linux linux kernel 2.6.15.5

linux linux kernel 2.6.6

linux linux kernel 2.6_test9_cvs

Vendor Advisories

The sys_mbind() function did not properly verify the validity of the ‘maxnod’ argument A local user could exploit this to trigger a buffer overflow, which caused a kernel crash (CVE-2006-0557) ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3359 Franz Filz discovered that some socket calls permit causing inconsistent reference count ...