USN-3445-1
Dashboard / Vulnerabilities / USN-3445-1
USN-3445-1
Summary: linux vulnerabilities
Details: Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation in the Linux kernel contained a buffer overflow when handling fragmented packets. A remote attacker could use this to possibly execute arbitrary code with administrative privileges. (CVE-2016-8633) Andrey Konovalov discovered that a divide-by-zero error existed in the TCP stack implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-14106)
References: https://ubuntu.com/security/notices/USN-3445-1, https://ubuntu.com/security/CVE-2016-8633, https://ubuntu.com/security/CVE-2017-14106
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
