CVE-2016-5696

CVSS v3.0 4.8 (Medium)
48% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.45 % (75th)
0.45% Progress
Affected Products 3
Advisories 27

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2016-08-06 20:59:05
(8 years ago)
Updated Date
2021-11-17 22:15:54
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Google Android 7.0 and prior versions cpe:2.3:o:google:android <= 7.0

Configuration #2

    CPE23 From Up To
  Oracle Vm Server 3.3 cpe:2.3:a:oracle:vm_server:3.3
  Oracle Vm Server 3.4 cpe:2.3:a:oracle:vm_server:3.4

Configuration #3

    CPE23 From Up To
  Linux Kernel 4.6.6 and prior versions cpe:2.3:o:linux:linux_kernel <= 4.6.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...