CVE-2015-6496: Medium severity conntrack-tools vulnerability
Published Aug 24, 2015
·Updated
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
Affected Software
3 affected components
netfilter Conntrack-tools<=1.4.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Event History
Aug 24, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
Which systems are exposed to this denial-of-service issue?
Systems running conntrackd from conntrack-tools 1.4.2 or earlier are affected when the relevant optional kernel modules are not loaded. The issue applies to handling of DCCP, SCTP, or ICMPv6 traffic.
2
What does an attacker need to do to trigger the crash?
An unauthenticated remote attacker can send a DCCP, SCTP, or ICMPv6 packet. The attack does not require prior access or user interaction.
3
Is a fix available?
Yes. A patch is available.