5
CVSSv2

CVE-2015-6496

Published: 24/08/2015 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

conntrackd in conntrack-tools 1.4.2 and previous versions does not ensure that the optional kernel modules are loaded before using them, which allows remote malicious users to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.

Vulnerable Product Search on Vulmon Subscribe to Product

netfilter conntrack-tools

debian debian linux 8.0

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #796103 conntrack: CVE-2015-6496: conntrackd crash on unexpected network traffic Package: conntrack; Maintainer for conntrack is Debian Netfilter Packaging Team <pkg-netfilter-team@listsaliothdebianorg>; Source for conntrack is src:conntrack-tools (PTS, buildd, popcon) Reported by: Moritz Muehlenh ...
It was discovered that in certain configurations, if the relevant conntrack kernel module is not loaded, conntrackd will crash when handling DCCP, SCTP or ICMPv6 packets For the oldstable distribution (wheezy), this problem has been fixed in version 1:121-1+deb7u1 For the stable distribution (jessie), this problem has been fixed in version 1:1 ...