|
|
| |
|
| |
net6: multiple vulnerabilities
| Package(s): | net6 |
CVE #(s): | CVE-2011-4093
CVE-2011-4091
|
| Created: | November 25, 2011 |
Updated: | January 5, 2012 |
| Description: |
From the Red Hat bugzilla::
Vasiliy Kulikov reported that libnet6 did not check the
basic_server::id_counter for integer overflows. This number is used to
distinguish different users, so an attacker that was able to open UINT_MAX
successive connections could get an identifier of an already existing
connection, allowing them to hijack that user's connection. (CVE-2011-4093)
Red Hat bugzilla:
Vasiliy Kulikov reported that libnet6 would check for user color collisions
prior to authentication. This could allow for the disclosure of certain user information by users that were not authenticated. (CVE-2011-4091)
|
| Alerts: |
|
( Log in to post comments)
|
|
|