Upstream information

CVE-2013-0343 at MITRE

Description

The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 3.2
Vector AV:A/AC:H/Au:N/C:P/I:N/A:P
Access Vector Adjacent Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 805226 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP1-LTSS
  • btrfs-kmp-default >= 0_2.6.32.59_0.9-0.3.151
  • btrfs-kmp-pae >= 0_2.6.32.59_0.13-0.3.163
  • btrfs-kmp-xen >= 0_2.6.32.59_0.9-0.3.151
  • ext4dev-kmp-default >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-pae >= 0_2.6.32.59_0.13-7.9.130
  • ext4dev-kmp-trace >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-xen >= 0_2.6.32.59_0.9-7.9.118
  • hyper-v-kmp-default >= 0_2.6.32.59_0.9-0.18.37
  • hyper-v-kmp-pae >= 0_2.6.32.59_0.13-0.18.39
  • hyper-v-kmp-trace >= 0_2.6.32.59_0.9-0.18.37
  • kernel-default >= 2.6.32.59-0.9.1
  • kernel-default-base >= 2.6.32.59-0.9.1
  • kernel-default-devel >= 2.6.32.59-0.9.1
  • kernel-default-man >= 2.6.32.59-0.15.2
  • kernel-ec2 >= 2.6.32.59-0.9.1
  • kernel-ec2-base >= 2.6.32.59-0.9.1
  • kernel-ec2-devel >= 2.6.32.59-0.9.1
  • kernel-pae >= 2.6.32.59-0.15.2
  • kernel-pae-base >= 2.6.32.59-0.15.2
  • kernel-pae-devel >= 2.6.32.59-0.15.2
  • kernel-source >= 2.6.32.59-0.9.1
  • kernel-syms >= 2.6.32.59-0.9.1
  • kernel-trace >= 2.6.32.59-0.9.1
  • kernel-trace-base >= 2.6.32.59-0.9.1
  • kernel-trace-devel >= 2.6.32.59-0.9.1
  • kernel-xen >= 2.6.32.59-0.9.1
  • kernel-xen-base >= 2.6.32.59-0.9.1
  • kernel-xen-devel >= 2.6.32.59-0.9.1
  • xen-kmp-default >= 4.0.3_21548_18_2.6.32.59_0.19-0.9.17
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.15-0.5.26
  • xen-kmp-trace >= 4.0.3_21548_18_2.6.32.59_0.19-0.9.17
Patchnames:
slessp1-kernel
SUSE Linux Enterprise Server 10 SP3 LTSS for x86
  • kernel-bigsmp >= 2.6.16.60-0.123.1
  • kernel-debug >= 2.6.16.60-0.123.1
  • kernel-default >= 2.6.16.60-0.123.1
  • kernel-kdump >= 2.6.16.60-0.123.1
  • kernel-kdumppae >= 2.6.16.60-0.123.1
  • kernel-smp >= 2.6.16.60-0.123.1
  • kernel-source >= 2.6.16.60-0.123.1
  • kernel-syms >= 2.6.16.60-0.123.1
  • kernel-vmi >= 2.6.16.60-0.123.1
  • kernel-vmipae >= 2.6.16.60-0.123.1
  • kernel-xen >= 2.6.16.60-0.123.1
  • kernel-xenpae >= 2.6.16.60-0.123.1
Builds
ZYPP Patch Nr: 8876
SUSE Linux Enterprise Server 10 SP3 LTSS for IBM zSeries 64bit
  • kernel-default >= 2.6.16.60-0.123.1
  • kernel-source >= 2.6.16.60-0.123.1
  • kernel-syms >= 2.6.16.60-0.123.1
Builds
ZYPP Patch Nr: 8878
SUSE Linux Enterprise Server 11 SP1 LTSS
  • btrfs-kmp-default >= 0_2.6.32.59_0.9-0.3.151
  • btrfs-kmp-xen >= 0_2.6.32.59_0.9-0.3.151
  • ext4dev-kmp-default >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-trace >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-xen >= 0_2.6.32.59_0.9-7.9.118
  • hyper-v-kmp-default >= 0_2.6.32.59_0.9-0.18.37
  • hyper-v-kmp-trace >= 0_2.6.32.59_0.9-0.18.37
  • kernel-default >= 2.6.32.59-0.9.1
  • kernel-default-base >= 2.6.32.59-0.9.1
  • kernel-default-devel >= 2.6.32.59-0.9.1
  • kernel-ec2 >= 2.6.32.59-0.9.1
  • kernel-ec2-base >= 2.6.32.59-0.9.1
  • kernel-ec2-devel >= 2.6.32.59-0.9.1
  • kernel-source >= 2.6.32.59-0.9.1
  • kernel-syms >= 2.6.32.59-0.9.1
  • kernel-trace >= 2.6.32.59-0.9.1
  • kernel-trace-base >= 2.6.32.59-0.9.1
  • kernel-trace-devel >= 2.6.32.59-0.9.1
  • kernel-xen >= 2.6.32.59-0.9.1
  • kernel-xen-base >= 2.6.32.59-0.9.1
  • kernel-xen-devel >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8849
SLE 11 SERVER Unsupported Extras
  • kernel-default-extra >= 2.6.32.59-0.9.1
  • kernel-pae-extra >= 2.6.32.59-0.9.1
  • kernel-xen-extra >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8850
SLE 11 SERVER Unsupported Extras
  • kernel-default-extra >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8851
SUSE Linux Enterprise Server 10 SP3 LTSS for AMD64 and Intel EM64T
  • kernel-debug >= 2.6.16.60-0.123.1
  • kernel-default >= 2.6.16.60-0.123.1
  • kernel-kdump >= 2.6.16.60-0.123.1
  • kernel-smp >= 2.6.16.60-0.123.1
  • kernel-source >= 2.6.16.60-0.123.1
  • kernel-syms >= 2.6.16.60-0.123.1
  • kernel-xen >= 2.6.16.60-0.123.1
Builds
ZYPP Patch Nr: 8877
SUSE Linux Enterprise Server 10 SP4 LTSS for IBM zSeries 64bit
  • kernel-default >= 2.6.16.60-0.105.1
  • kernel-source >= 2.6.16.60-0.105.1
  • kernel-syms >= 2.6.16.60-0.105.1
Builds
ZYPP Patch Nr: 8816
SLE 11 SERVER Unsupported Extras
  • kernel-default-extra >= 2.6.32.59-0.9.1
  • kernel-xen-extra >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8852
SUSE Linux Enterprise Server 11 SP1 LTSS
  • btrfs-kmp-default >= 0_2.6.32.59_0.9-0.3.151
  • btrfs-kmp-pae >= 0_2.6.32.59_0.9-0.3.151
  • btrfs-kmp-xen >= 0_2.6.32.59_0.9-0.3.151
  • ext4dev-kmp-default >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-pae >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-trace >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-xen >= 0_2.6.32.59_0.9-7.9.118
  • hyper-v-kmp-default >= 0_2.6.32.59_0.9-0.18.37
  • hyper-v-kmp-pae >= 0_2.6.32.59_0.9-0.18.37
  • hyper-v-kmp-trace >= 0_2.6.32.59_0.9-0.18.37
  • kernel-default >= 2.6.32.59-0.9.1
  • kernel-default-base >= 2.6.32.59-0.9.1
  • kernel-default-devel >= 2.6.32.59-0.9.1
  • kernel-ec2 >= 2.6.32.59-0.9.1
  • kernel-ec2-base >= 2.6.32.59-0.9.1
  • kernel-ec2-devel >= 2.6.32.59-0.9.1
  • kernel-pae >= 2.6.32.59-0.9.1
  • kernel-pae-base >= 2.6.32.59-0.9.1
  • kernel-pae-devel >= 2.6.32.59-0.9.1
  • kernel-source >= 2.6.32.59-0.9.1
  • kernel-syms >= 2.6.32.59-0.9.1
  • kernel-trace >= 2.6.32.59-0.9.1
  • kernel-trace-base >= 2.6.32.59-0.9.1
  • kernel-trace-devel >= 2.6.32.59-0.9.1
  • kernel-xen >= 2.6.32.59-0.9.1
  • kernel-xen-base >= 2.6.32.59-0.9.1
  • kernel-xen-devel >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8847
SUSE Linux Enterprise Server 10 SP4 LTSS for AMD64 and Intel EM64T
  • kernel-debug >= 2.6.16.60-0.105.1
  • kernel-default >= 2.6.16.60-0.105.1
  • kernel-kdump >= 2.6.16.60-0.105.1
  • kernel-smp >= 2.6.16.60-0.105.1
  • kernel-source >= 2.6.16.60-0.105.1
  • kernel-syms >= 2.6.16.60-0.105.1
  • kernel-xen >= 2.6.16.60-0.105.1
Builds
ZYPP Patch Nr: 8818
SUSE Linux Enterprise Server 10 SP4 LTSS for x86
  • kernel-bigsmp >= 2.6.16.60-0.105.1
  • kernel-debug >= 2.6.16.60-0.105.1
  • kernel-default >= 2.6.16.60-0.105.1
  • kernel-kdump >= 2.6.16.60-0.105.1
  • kernel-kdumppae >= 2.6.16.60-0.105.1
  • kernel-smp >= 2.6.16.60-0.105.1
  • kernel-source >= 2.6.16.60-0.105.1
  • kernel-syms >= 2.6.16.60-0.105.1
  • kernel-vmi >= 2.6.16.60-0.105.1
  • kernel-vmipae >= 2.6.16.60-0.105.1
  • kernel-xen >= 2.6.16.60-0.105.1
  • kernel-xenpae >= 2.6.16.60-0.105.1
Builds
ZYPP Patch Nr: 8817
SUSE Linux Enterprise Server 11 SP1 LTSS
  • btrfs-kmp-default >= 0_2.6.32.59_0.9-0.3.151
  • ext4dev-kmp-default >= 0_2.6.32.59_0.9-7.9.118
  • ext4dev-kmp-trace >= 0_2.6.32.59_0.9-7.9.118
  • kernel-default >= 2.6.32.59-0.9.1
  • kernel-default-base >= 2.6.32.59-0.9.1
  • kernel-default-devel >= 2.6.32.59-0.9.1
  • kernel-default-man >= 2.6.32.59-0.9.1
  • kernel-source >= 2.6.32.59-0.9.1
  • kernel-syms >= 2.6.32.59-0.9.1
  • kernel-trace >= 2.6.32.59-0.9.1
  • kernel-trace-base >= 2.6.32.59-0.9.1
  • kernel-trace-devel >= 2.6.32.59-0.9.1
Builds
SAT Patch Nr: 8848


Status of this issue by product and package

Product(s) Source package State
SUSE Linux Enterprise Desktop 10 SP3 kernel-source Released
SUSE Linux Enterprise Desktop 10 SP4 kernel-source Released
SUSE Linux Enterprise Desktop 11 SP1 kernel-source Released
SUSE Linux Enterprise Server 10 SP3 kernel-source Released
SUSE Linux Enterprise Server 10 SP4 kernel-source Released
SUSE Linux Enterprise Server 10 SP4 LTSS kernel-source Released
SUSE Linux Enterprise Server 11 SP1 kernel-source Released
SUSE Linux Enterprise Server 11 SP1 LTSS kernel-source Released
SUSE Linux Enterprise Server for SAP AIO 11 SP1 kernel-source Released