UBUNTU-CVE-2014-2523
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-2523
UBUNTU-CVE-2014-2523
Summary:
Details: net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a DCCP packet that triggers a call to the (1) dccp_new, (2) dccp_packet, or (3) dccp_error function.
References: https://ubuntu.com/security/CVE-2014-2523, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/nf_conntrack_proto_dccp.c?id=b22f5126a24b3b2f15448c3f2a254fc10cbc2b92, https://ubuntu.com/security/notices/USN-2173-1, https://ubuntu.com/security/notices/USN-2174-1, https://ubuntu.com/security/notices/USN-2221-1, https://ubuntu.com/security/notices/USN-2223-1, https://ubuntu.com/security/notices/USN-2224-1, https://ubuntu.com/security/notices/USN-2225-1, https://ubuntu.com/security/notices/USN-2227-1, https://ubuntu.com/security/notices/USN-2228-1, https://www.cve.org/CVERecord?id=CVE-2014-2523
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
