Candidate: CVE-2015-6496 PublicDate: 2015-08-24 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6496 http://www.openwall.com/lists/oss-security/2015/08/14/4 Description: conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet. Ubuntu-Description: Notes: Bugs: http://bugzilla.netfilter.org/show_bug.cgi?id=910 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796103 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_conntrack: upstream: https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd upstream_conntrack: needs-triage precise_conntrack: ignored (reached end-of-life) precise/esm_conntrack: DNE (precise was needed) trusty_conntrack: ignored (reached end-of-life) trusty/esm_conntrack: DNE (trusty was needed) vivid_conntrack: ignored (reached end-of-life) vivid/stable-phone-overlay_conntrack: DNE vivid/ubuntu-core_conntrack: DNE wily_conntrack: released (1:1.4.2-3ubuntu1) xenial_conntrack: DNE yakkety_conntrack: DNE zesty_conntrack: DNE artful_conntrack: DNE bionic_conntrack: DNE cosmic_conntrack: DNE disco_conntrack: DNE devel_conntrack: DNE Patches_conntrack-tools: upstream: https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd upstream_conntrack-tools: needs-triage precise_conntrack-tools: DNE precise/esm_conntrack-tools: DNE trusty_conntrack-tools: DNE trusty/esm_conntrack-tools: DNE vivid_conntrack-tools: DNE vivid/stable-phone-overlay_conntrack-tools: DNE vivid/ubuntu-core_conntrack-tools: DNE wily_conntrack-tools: DNE xenial_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) esm-infra/xenial_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) yakkety_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) zesty_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) artful_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) bionic_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) cosmic_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) disco_conntrack-tools: not-affected (1:1.4.2-3ubuntu1) devel_conntrack-tools: not-affected (1:1.4.2-3ubuntu1)