CVE-2013-0343
Published: 28 February 2013
The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.
From the Ubuntu security team
An information leak was discovered in the handling of ICMPv6 Router Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A remote attacker could exploit this flaw to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information.
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-armadaxp Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-aws Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-ec2 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-flo Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-fsl-imx51 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-gke Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-goldfish Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-grouper Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-hwe Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-linaro-omap Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-linaro-shared Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-linaro-vexpress Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-backport-maverick Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-backport-oneiric Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-quantal Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-raring Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-saucy Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-trusty Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-utopic Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-vivid Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-wily Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-maguro Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-mako Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-manta Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-mvl-dove Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-qcm-msm Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-raspi2 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-snapdragon Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
linux-ti-omap4 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.11~rc7)
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343
- https://bugzilla.redhat.com/show_bug.cgi?id=914664
- http://www.openwall.com/lists/oss-security/2013/02/22/6
- http://openwall.com/lists/oss-security/2013/01/21/11
- http://openwall.com/lists/oss-security/2013/01/16/7
- http://openwall.com/lists/oss-security/2012/12/05/4
- https://ubuntu.com/security/notices/USN-1976-1
- https://ubuntu.com/security/notices/USN-1977-1
- https://ubuntu.com/security/notices/USN-2019-1
- https://ubuntu.com/security/notices/USN-2020-1
- https://ubuntu.com/security/notices/USN-2021-1
- https://ubuntu.com/security/notices/USN-2022-1
- https://ubuntu.com/security/notices/USN-2023-1
- https://ubuntu.com/security/notices/USN-2024-1
- https://ubuntu.com/security/notices/USN-2038-1
- https://ubuntu.com/security/notices/USN-2039-1
- https://ubuntu.com/security/notices/USN-2050-1
- NVD
- Launchpad
- Debian