BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://www.exploitalert.com/view-details.html?id=26361 | third party advisory exploit |
https://backbox.org/portal/blog/false-cve-backbox-46-unmasked | vendor advisory |
https://cxsecurity.com/issue/WLB-2017040001 | third party advisory exploit |
https://forum.backbox.org/security-advisories/waiting-verification-backbox-os-denial-of-service/msg10218 | vendor advisory |
https://www.exploit-db.com/exploits/41781/ | exploit vdb entry third party advisory |