CVE-2012-2320: High severity connman vulnerability
ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of service via a crafted netlink message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2320?
CVE-2012-2320 is considered a moderate severity vulnerability as it allows remote attackers to cause a denial of service.
How do I fix CVE-2012-2320?
To fix CVE-2012-2320, update ConnMan to version 0.85 or later, where this issue has been addressed.
What type of attack is possible with CVE-2012-2320?
CVE-2012-2320 enables attackers to send crafted netlink messages that can bypass access restrictions and potentially crash the system.
Which versions of ConnMan are affected by CVE-2012-2320?
CVE-2012-2320 affects ConnMan versions prior to 0.85, including all versions from 0.1 to 0.84.
Is CVE-2012-2320 exploitable remotely?
Yes, CVE-2012-2320 is exploitable remotely, allowing attackers to send malicious messages without physical access to the device.