VDB
CVE-2015-6496
CVE-2015-6496
PUBLISHED
CVSS 5 MEDIUM
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
EPSS 2.79% · 86.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.79%
86.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 7.0, 8.0 |
| n/a | n/a | n/a |
| netfilter | conntrack-tools | 0 |
Timeline
- Aug 24, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- FEDORA-2015-5eb2131441 vendor-advisory
- [oss-security] 20150817 Re: CVE request: conntrackd denial of service with unusual network traffic mailing-list
- https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd url
- FEDORA-2015-1aee5e6f0b vendor-advisory
- [oss-security] 20150814 CVE request: conntrackd denial of service with unusual network traffic mailing-list
- openSUSE-SU-2015:1688 vendor-advisory
- http://bugzilla.netfilter.org/show_bug.cgi?id=910 url
- DSA-3341 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-6496 advisory