CVE-2015-0272: Medium severity red hat networkmanager-libreswan-gnome vulnerability
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
Other sources
It was reported [1] that it's possible to craft a Router Advertisement message which will bring the receiver in a state where new IPv6 connections will not be accepted until correct Router Advertisement message received.
[1]: https://bugzilla.redhat.com/showbug.cgi?id=1183051#c3
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-0272?
CVE-2015-0272 is a vulnerability in GNOME NetworkManager that allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message.
How severe is CVE-2015-0272?
CVE-2015-0272 has a medium severity level.
Which software versions are affected by CVE-2015-0272?
CVE-2015-0272 affects Ubuntu Linux versions 4.0~ up to, but not including, 4.0~, Ubuntu Linux versions 3.2.0-93.133 up to, but not including, 3.2.0-93.133, Ubuntu Linux versions 3.13.0-66.108 up to, but not including, 3.13.0-66.108, and Ubuntu Linux versions 3.19.0-31.36 up to, but not including, 3.19.0-31.36.
How can I fix CVE-2015-0272?
To fix CVE-2015-0272, users should update to a version of Ubuntu Linux that is not vulnerable to the issue.
Where can I find more information about CVE-2015-0272?
More information about CVE-2015-0272 can be found at the following references: [1] http://www.securityfocus.com/bid/76814 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1192132 [3] http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html