CVE-2006-4572
Linux Kernel < 2.6.16.31 - ip6_tables Protocol and Extension Header Bypass
Title source: llmDescription
ip6_tables in netfilter in the Linux kernel before 2.6.16.31 allows remote attackers to (1) bypass a rule that disallows a protocol, via a packet with the protocol header not located immediately after the fragment header, aka "ip6_tables protocol bypass bug;" and (2) bypass a rule that looks for a certain extension header, via a packet with an extension header outside the first fragment, aka "ip6_tables extension header bypass bug."
References (18)
Core 18
Core References
Vendor Advisory x_refsource_confirm
http://www.kernel.org/git/?p=linux%2Fkernel%2Fgit%2Fstable%2Flinux-2.6.16.y.git&a=search&s=CVE-2006-4572
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24098
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_79_kernel.html
Vendor Advisory x_refsource_confirm
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git%3Ba=commit%3Bh=6ac62be885810e1f8390f0c3b9d3ee451d3d3f19
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23384
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-416-1
Patch mailing-list
x_refsource_mlist
http://readlist.com/lists/vger.kernel.org/linux-kernel/55/275979.html
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22762
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4386
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23474
Vendor Advisory x_refsource_confirm
http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git%3Ba=commit%3Bh=0ddfcc96928145d6a6425fdd26dad6abfe7f891d
Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.31
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/471457
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-395-1
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22731
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:197
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25691
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/20955
Scores
EPSS
0.0363
EPSS Percentile
88.5%
Details
CWE
CWE-264
Status
published
Products (13)
linux/linux_kernel
2.6.0
linux/linux_kernel
2.6.1 (4 CPE variants)
linux/linux_kernel
2.6.2 (4 CPE variants)
linux/linux_kernel
2.6.3 (5 CPE variants)
linux/linux_kernel
2.6.4 (4 CPE variants)
linux/linux_kernel
2.6.5 (4 CPE variants)
linux/linux_kernel
2.6.6 (4 CPE variants)
linux/linux_kernel
2.6.7 (4 CPE variants)
linux/linux_kernel
2.6.8 (5 CPE variants)
linux/linux_kernel
2.6.8.1
... and 3 more
Published
Nov 07, 2006
Tracked Since
Feb 18, 2026