LWN.net Logo

net6: multiple vulnerabilities

Package(s):net6 CVE #(s):CVE-2011-4093 CVE-2011-4091
Created:November 25, 2011 Updated:January 5, 2012
Description: From the Red Hat bugzilla::

Vasiliy Kulikov reported that libnet6 did not check the basic_server::id_counter for integer overflows. This number is used to distinguish different users, so an attacker that was able to open UINT_MAX successive connections could get an identifier of an already existing connection, allowing them to hijack that user's connection. (CVE-2011-4093)

Red Hat bugzilla:

Vasiliy Kulikov reported that libnet6 would check for user color collisions prior to authentication. This could allow for the disclosure of certain user information by users that were not authenticated. (CVE-2011-4091)

Alerts:
Fedora FEDORA-2011-15332 2011-11-03
Fedora FEDORA-2011-15326 2011-11-03
Fedora FEDORA-2011-15363 2011-11-03
openSUSE openSUSE-SU-2012:0008-1 2012-01-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds