Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
BID:41524
Info
Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
| Bugtraq ID: | 41524 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2010-2522 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 09 2010 12:00AM |
| Updated: | Apr 13 2015 10:14PM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
Usagi Project mipv6-daemon 6 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 |
| Not Vulnerable: | |
Discussion
Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
Usagi Project mipv6-daemon is prone to a vulnerability that allows attackers to spoof kernel messages.
An attacker can exploit this issue to spoof the origin of Unicast messages, which may aid in further attacks.
Usagi Project mipv6-daemon is prone to a vulnerability that allows attackers to spoof kernel messages.
An attacker can exploit this issue to spoof the origin of Unicast messages, which may aid in further attacks.
Exploit / POC
Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
Local attackers can exploit this issue with readily available tools.
Local attackers can exploit this issue with readily available tools.
Solution / Fix
Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Usagi Project mipv6-daemon Unicast Kernel Message Spoofing Vulnerability
References:
References:
- patch for remote buffer overflows and local message spoofing in mipv6 daemon (Sebastian Krahmer)
- USAGI Project - Linux IPv6 Development Project Homepage (USAGI Project)