8.5
CVSSv2

CVE-2013-5385

Published: 02/01/2014 Updated: 28/01/2014
CVSS v2 Base Score: 8.5 | Impact Score: 7.8 | Exploitability Score: 10
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:C

Vulnerability Summary

The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote malicious users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm i 7.1

ibm z\\/os

ibm i 6.1