First published: Thu Feb 12 2015(Updated: )
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME NetworkManager | <1.2.0 | |
SUSE Linux Enterprise Debuginfo | =11-sp2 | |
SUSE Linux Enterprise Debuginfo | =11-sp3 | |
SUSE Linux Enterprise Debuginfo | =11-sp4 | |
SUSE Linux Enterprise Desktop | =11-sp3 | |
SUSE Linux Enterprise Desktop | =11-sp4 | |
SUSE Linux Enterprise Desktop | =12 | |
SUSE Linux Enterprise Desktop | =12-sp1 | |
Suse Linux Enterprise Real Time Extension | =11-sp3 | |
Suse Linux Enterprise Real Time Extension | =11-sp4 | |
SUSE Linux Enterprise Server | =11 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
Suse Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Software Development Kit | =11-sp3 | |
SUSE Linux Enterprise Software Development Kit | =11-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12 | |
SUSE Linux Enterprise Software Development Kit | =12-sp1 | |
Suse Linux Enterprise Workstation Extension | =12 | |
Suse Linux Enterprise Workstation Extension | =12-sp1 | |
Canonical Ubuntu Linux | =12.04 | |
Oracle Linux | =7 | |
debian/network-manager | 1.30.6-1+deb11u1 1.42.4-1 1.50.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0272 is a vulnerability in GNOME NetworkManager that allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message.
CVE-2015-0272 has a medium severity level.
CVE-2015-0272 affects Ubuntu Linux versions 4.0~ up to, but not including, 4.0~, Ubuntu Linux versions 3.2.0-93.133 up to, but not including, 3.2.0-93.133, Ubuntu Linux versions 3.13.0-66.108 up to, but not including, 3.13.0-66.108, and Ubuntu Linux versions 3.19.0-31.36 up to, but not including, 3.19.0-31.36.
To fix CVE-2015-0272, users should update to a version of Ubuntu Linux that is not vulnerable to the issue.
More information about CVE-2015-0272 can be found at the following references: [1] http://www.securityfocus.com/bid/76814 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1192132 [3] http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html