CVE-2015-0272

Impact:
Moderate
Public Date:
2015-02-23
CWE:
CWE-20
Bugzilla:
1192132: CVE-2015-0272 NetworkManager: remote DoS using IPv6 RA with bogus MTU
It was discovered that NetworkManager would set device MTUs based on MTU values received in IPv6 RAs (Router Advertisements), without sanity checking the MTU value first. A remote attacker could exploit this flaw to create a denial of service attack, by sending a specially crafted IPv6 RA packet to disturb IPv6 communication.

Find out more about CVE-2015-0272 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (NetworkManager) RHSA-2015:2315 2015-11-19

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 NetworkManager Not affected
Red Hat Enterprise Linux 5 NetworkManager Not affected

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.