CVE-2009-4536

CVSS v2.0 7.8 (High)
78% Progress
EPSS 1.77 % (88th)
1.77% Progress
Affected Products 2
Advisories 5

drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.

Weaknesses
CWE-189
Numeric Errors
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2010-01-12 17:30:00
(14 years ago)
Updated Date
2018-11-16 15:51:54
(5 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 2.6.32.3 and prior versions cpe:2.3:o:linux:linux_kernel <= 2.6.32.3

Configuration #2

    CPE23 From Up To
  Debian Linux 4.0 cpe:2.3:o:debian:debian_linux:4.0
  Debian Linux 5.0 cpe:2.3:o:debian:debian_linux:5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...