Tuesday, August 16, 2016

Vulnerability Summary for CVE-2016-5696

Vulnerability Summary for CVE-2016-5696

Original release date: 08/06/2016
Last revised: 08/10/2016
Source: US-CERT/NIST

Overview

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for man-in-the-middle attackers to hijack TCP sessions via a blind in-window attack.

Impact

CVSS Severity (version 3.0):
CVSS v3 Base Score: 5.9 Medium
Impact Score: 3.6
Exploitability Score: 2.2
CVSS Version 3 Metrics:
Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): None
Availability (A): None
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 MEDIUM
Impact Subscore: 2.9
Exploitability Subscore: 8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized disclosure of information

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
External Source: MISC
Name: http://www.prnewswire.com/news-releases/mitnick-attack-reappears-at-geekpwn-macau-contest-300270779.html
Type: Technical Description
External Source: MLIST
Name: [oss-security] 20160712 Re: CVE-2016-5389: linux kernel - challange ack information leak.
Type: Mailing List; Third Party Advisory
External Source: CONFIRM
Name: https://bugzilla.redhat.com/show_bug.cgi?id=1354708
Type: Issue Tracking
External Source: CONFIRM
Name: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=75ff39ccc1bd5d3c455b6822ab09e533c551f758
Type: Issue Tracking; Patch
External Source: CONFIRM
Name: https://github.com/torvalds/linux/commit/75ff39ccc1bd5d3c455b6822ab09e533c551f758
Type: Issue Tracking; Patch

Vulnerable software and versions

+ Configuration 1
* OR
* cpe:/o:linux:linux_kernel:4.6.6 and previous versions

* Denotes Vulnerable Software
Changes related to vulnerability configurations

Technical Details

Vulnerability Type (View All)
  • Information Leak / Disclosure (CWE-200)



- wong chee tat :)

No comments: