CVE-2011-4913: Buffer Overflow
Last updated 24 July 2024
Other sources
The roseparseccitt function in net/rose/rosesubr.c in the Linux kernel before 2.6.39 does not validate the FACCCITTDESTNSAP and FACCCITTSRCNSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4913?
CVE-2011-4913 is classified as a high severity vulnerability due to its potential to cause denial of service and heap memory corruption.
How do I fix CVE-2011-4913?
To fix CVE-2011-4913, update your Linux kernel to version 2.6.39 or later, where the vulnerability has been addressed.
What versions of the Linux kernel are affected by CVE-2011-4913?
CVE-2011-4913 affects Linux kernel versions prior to 2.6.39, including 2.6.38 and earlier releases.
What types of attacks can CVE-2011-4913 facilitate?
CVE-2011-4913 may allow remote attackers to exploit the vulnerability to cause denial of service through heap memory corruption.
Is CVE-2011-4913 present in any specific Linux distributions?
Yes, CVE-2011-4913 has been identified in various distributions such as Debian's linux-2.6 and SUSE Linux Enterprise Server version 10.0-sp4.