CVE-2011-1173
Last modified
CVE-2011-1173 is a vulnerability of currently unknown severity. The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.. EPSS estimates a 2.61% chance of exploitation in the next 30 days.
Description
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.39 |
References
- http://marc.info/?l=linux-netdev&m=130036203528021&w=2Patch, Third Party Advisory
- http://securityreason.com/securityalert/8279Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/03/18/15Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/4Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14Issue Tracking, Third Party Advisory
- http://marc.info/?l=linux-netdev&m=130036203528021&w=2Patch, Third Party Advisory
- http://securityreason.com/securityalert/8279Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/03/18/15Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/4Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1173?
How severe is CVE-2011-1173?
How do I fix CVE-2011-1173?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-1167Heap-based buffer overflow in the thunder (aka ThunderScan) …
- CVE-2011-1168Cross-site scripting (XSS) vulnerability in the KHTMLPart::h…
- CVE-2011-1169Array index error in the asihpi_hpi_ioctl function in sound/…
- CVE-2011-1170net/ipv4/netfilter/arp_tables.c in the IPv4 implementation i…
- CVE-2011-1171net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in…
- CVE-2011-1172net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation i…
- CVE-2011-1174manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1…
- CVE-2011-1175tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1…
- CVE-2011-1176The configuration merger in itk.c in the Steinar H. Gunderso…
- CVE-2011-1177Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-1178Multiple integer overflows in the load_image function in fil…
- CVE-2011-1179The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and pos…
Are you affected by CVE-2011-1173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
