5
CVSSv2

CVE-2010-3873

Published: 03/01/2011 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The X.25 implementation in the Linux kernel prior to 2.6.36.2 does not properly parse facilities, which allows remote malicious users to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

suse linux enterprise server 9

opensuse opensuse 11.4

debian debian linux 5.0

Vendor Advisories

Tavis Ormandy discovered that the Linux kernel did not properly implement exception fixup A local attacker could exploit this to crash the kernel, leading to a denial of service (CVE-2010-3086) ...
Multiple kernel flaws have been fixed ...
An attacker could send crafted input to the kernel and cause it to crash ...
Several security issues were fixed in the kernel ...