| Severity : |
High
|
| Published : |
2011-07-18
|
| Modified : |
2012-03-19
|
| Base Score : |
7.8
|
| Details : |
The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
|
| Product/Version : |
Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'
Professional PRO 5.0
Professional PRO 5.0
CGE 5.x
Mobilinux 5.x
|
|
CVE Vulnerabilities List CVE-2011