CVE-2006-1343: Low severity Linux Linux kernel vulnerability
net/ipv4/netfilter/ipconntrackcore.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nfconntrackl3protoipv4.c in 2.6, does not clear sockaddrin.sinzero before returning IPv4 socket names from the getsockopt function with SOORIGINALDST, which allows local users to obtain portions of potentially sensitive memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1343?
CVE-2006-1343 is classified as a medium severity vulnerability that can potentially allow local users to gain sensitive information.
How do I fix CVE-2006-1343?
To fix CVE-2006-1343, it is recommended to upgrade to a patched version of the Linux kernel that addresses this vulnerability.
What systems are affected by CVE-2006-1343?
CVE-2006-1343 affects Linux kernel versions 2.4.0 and 2.6.0.
What type of vulnerability is CVE-2006-1343?
CVE-2006-1343 is a local information disclosure vulnerability related to socket options in the Linux kernel.
Who can exploit CVE-2006-1343?
CVE-2006-1343 can be exploited by local users who have access to the affected systems.