ShaikUsaf/linux-3.0.35

CVE-2016-4997 (High) detected in multiple libraries

Opened this issue · 0 comments

CVE-2016-4997 - High Severity Vulnerability

Vulnerable Libraries - linuxlinux-3.0.49, linuxlinux-3.0.49, linuxlinux-3.0.49, linux-stable-rtv3.8.6, linuxlinux-3.0.49

Vulnerability Details

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.

Publish Date: 2016-07-03

URL: CVE-2016-4997

CVSS 3 Score Details (7.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2016-4997

Release Date: 2016-07-03

Fix Resolution: 4.6.3


Step up your Open Source Security Game with Mend here