« Volver al listado

CVE-2011-4093

Estado: ModificadaMedia (5.8)—

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4093",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-02-10T18:15:09.153",
  "references": [
    {
      "url": "http://git.0x539.de/?p=net6.git%3Ba=commitdiff%3Bh=ac61d7fb42a1f977fb527e024bede319c4a9e169%3Bhp=08c8e2261604c6fcbbaf62f9ae9d13f7015fcb9a",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-01/msg00044.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-01/msg00054.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/10/31/1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=727710",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=750631",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://git.0x539.de/?p=net6.git%3Ba=commitdiff%3Bh=ac61d7fb42a1f977fb527e024bede319c4a9e169%3Bhp=08c8e2261604c6fcbbaf62f9ae9d13f7015fcb9a",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-01/msg00044.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-01/msg00054.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/10/31/1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=727710",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=750631",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de enteros en inc/server.hpp en libnet6 (también conocido como net6) anterior a 1.3.14 podría permitir a atacantes remotos secuestrar conexiones y ganar privilegios como otros usuarios mediante la realización de un gran número de conexiones hasta que el desbordamiento ocurre y la identidad de otro usuario es proporcionado."
    }
  ],
  "lastModified": "2026-06-16T23:34:24.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B1C288F-326B-497B-B26C-D26E01262DDB"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B580F7EF-BD7D-464F-ADEF-C387353D1C7A",
              "versionEndIncluding": "1.3.13"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75B0D417-BF61-45D1-AC4C-8E4753250BB4"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3E379A0-1F9E-46EF-8189-43D22BC5FA00"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71AD53FD-CF00-4D25-B8E0-738324135815"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB3767D8-BF27-4DA6-B630-BAE0EF2D80CD"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E44789AE-A92A-49E1-B820-C8208458D72F"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD774656-6E58-4CC5-8D52-4D3D0EC2C4B1"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E21AE2C-493D-44CC-8B17-A55E1FEDD39B"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AABB6CDB-27E1-4B59-8A72-D0D644929AA7"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD481E91-BBA1-474F-B5A0-EF3B145412A0"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDA498A1-D08C-4AA3-8849-6CCBBE306277"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C46815A-FF74-4C27-8AA6-6422FE4F695F"
            },
            {
              "criteria": "cpe:2.3:a:armin_burgmeier:net6:1.3.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A425163-5F20-4980-93B9-B433F0F79FD6"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5646FDE9-CF21-46A9-B89D-F5BBDB4249AF"
            },
            {
              "criteria": "cpe:2.3:o:opensuse_project:opensuse:11.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE8EFFB8-9411-4826-9BFC-A06BA042FC30"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}