ID

VAR-201604-0129


CVE

CVE-2016-3961


TITLE

Xen and Linux Kernel Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2016-002112

DESCRIPTION

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area. Xen is an open source virtual machine monitor product. Xen's PV virtual machine has a security vulnerability when enabling hugetlbfs support, allowing an attacker to exploit this vulnerability to trigger an infinite loop of error pages for a denial of service attack. (CVE-2016-1583) Multiple race conditions where discovered in the Linux kernel's ext4 file system. (CVE-2016-4486) Jann Horn discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel could overflow reference counters on systems with more than 32GB of physical ram and with RLIMIT_MEMLOCK set to infinite. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3607-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 28, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : linux CVE ID : CVE-2015-7515 CVE-2016-0821 CVE-2016-1237 CVE-2016-1583 CVE-2016-2117 CVE-2016-2143 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-3070 CVE-2016-3134 CVE-2016-3136 CVE-2016-3137 CVE-2016-3138 CVE-2016-3140 CVE-2016-3156 CVE-2016-3157 CVE-2016-3672 CVE-2016-3951 CVE-2016-3955 CVE-2016-3961 CVE-2016-4470 CVE-2016-4482 CVE-2016-4485 CVE-2016-4486 CVE-2016-4565 CVE-2016-4569 CVE-2016-4578 CVE-2016-4580 CVE-2016-4581 CVE-2016-4805 CVE-2016-4913 CVE-2016-4997 CVE-2016-4998 CVE-2016-5243 CVE-2016-5244 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2015-7515, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186, CVE-2016-2187, CVE-2016-3136, CVE-2016-3137, CVE-2016-3138, CVE-2016-3140 Ralf Spenneberg of OpenSource Security reported that various USB drivers do not sufficiently validate USB descriptors. This allowed a physically present user with a specially designed USB device to cause a denial of service (crash). CVE-2016-0821 Solar Designer noted that the list 'poisoning' feature, intended to mitigate the effects of bugs in list manipulation in the kernel, used poison values within the range of virtual addresses that can be allocated by user processes. CVE-2016-1237 David Sinquin discovered that nfsd does not check permissions when setting ACLs, allowing users to grant themselves permissions to a file by setting the ACL. CVE-2016-1583 Jann Horn of Google Project Zero reported that the eCryptfs filesystem could be used together with the proc filesystem to cause a kernel stack overflow. If the ecryptfs-utils package is installed, local users could exploit this, via the mount.ecryptfs_private program, for denial of service (crash) or possibly for privilege escalation. CVE-2016-2117 Justin Yackoski of Cryptonite discovered that the Atheros L2 ethernet driver incorrectly enables scatter/gather I/O. A remote attacker could take advantage of this flaw to obtain potentially sensitive information from kernel memory. CVE-2016-3070 Jan Stancek of Red Hat discovered a local denial of service vulnerability in AIO handling. CVE-2016-3134 The Google Project Zero team found that the netfilter subsystem does not sufficiently validate filter table entries. A user with the CAP_NET_ADMIN capability could use this for denial of service (crash) or possibly for privilege escalation. Debian disables unprivileged user namespaces by default, if locally enabled with the kernel.unprivileged_userns_clone sysctl, this allows privilege escalation. CVE-2016-3156 Solar Designer discovered that the IPv4 implementation in the Linux kernel did not perform the destruction of inet device objects properly. An attacker in a guest OS could use this to cause a denial of service (networking outage) in the host OS. CVE-2016-3157 / XSA-171 Andy Lutomirski discovered that the x86_64 (amd64) task switching implementation did not correctly update the I/O permission level when running as a Xen paravirtual (PV) guest. CVE-2016-3672 Hector Marco and Ismael Ripoll noted that it was possible to disable Address Space Layout Randomisation (ASLR) for x86_32 (i386) programs by removing the stack resource limit. This made it easier for local users to exploit security flaws in programs that have the setuid or setgid flag set. CVE-2016-3951 It was discovered that the cdc_ncm driver would free memory prematurely if certain errors occurred during its initialisation. This allowed a physically present user with a specially designed USB device to cause a denial of service (crash) or possibly to escalate their privileges. CVE-2016-3955 Ignat Korchagin reported that the usbip subsystem did not check the length of data received for a USB buffer. This allowed denial of service (crash) or privilege escalation on a system configured as a usbip client, by the usbip server or by an attacker able to impersonate it over the network. A system configured as a usbip server might be similarly vulnerable to physically present users. CVE-2016-3961 / XSA-174 Vitaly Kuznetsov of Red Hat discovered that Linux allowed the use of hugetlbfs on x86 (i386 and amd64) systems even when running as a Xen paravirtualised (PV) guest, although Xen does not support huge pages. CVE-2016-4470 David Howells of Red Hat discovered that a local user can trigger a flaw in the Linux kernel's handling of key lookups in the keychain subsystem, leading to a denial of service (crash) or possibly to privilege escalation. CVE-2016-4482, CVE-2016-4485, CVE-2016-4486, CVE-2016-4569, CVE-2016-4578, CVE-2016-4580, CVE-2016-5243, CVE-2016-5244 Kangjie Lu reported that the USB devio, llc, rtnetlink, ALSA timer, x25, tipc, and rds facilities leaked information from the kernel stack. CVE-2016-4565 Jann Horn of Google Project Zero reported that various components in the InfiniBand stack implemented unusual semantics for the write() operation. On a system with InfiniBand drivers loaded, local users could use this for denial of service or privilege escalation. CVE-2016-4581 Tycho Andersen discovered that in some situations the Linux kernel did not handle propagated mounts correctly. A local user can take advantage of this flaw to cause a denial of service (system crash). CVE-2016-4805 Baozeng Ding discovered a use-after-free in the generic PPP layer in the Linux kernel. A local user can take advantage of this flaw to cause a denial of service (system crash), or potentially escalate their privileges. CVE-2016-4913 Al Viro found that the ISO9660 filesystem implementation did not correctly count the length of certain invalid name entries. Reading a directory containing such name entries would leak information from kernel memory. Users permitted to mount disks or disk images could use this to obtain sensitive information. CVE-2016-4997 / CVE-2016-4998 Jesse Hertz and Tim Newsham discovered that missing input sanitising in Netfilter socket handling may result in denial of service. Debian disables unprivileged user namespaces by default, if locally enabled with the kernel.unprivileged_userns_clone sysctl, this also allows privilege escalation. For the stable distribution (jessie), these problems have been fixed in version 3.16.7-ckt25-2+deb8u2. We recommend that you upgrade your linux packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXckE+AAoJEAVMuPMTQ89EbVoP/2hxxkUZ6hmCNzqfAdVglANg xzBg+dWsE/1Q8gl2OiMrxV8Dy/v9+3Xl2lI0Lldx0zDRSqImvxzCm6Fhhye/OiRD BWeVdeHFdUNTv6MQQ9qFH6ykbz4TQhKPBbbCN0LbbsFa2I1LQNirvMM0fNu915U+ JgMP0JtkvbLZNzT8tg2hR+KkHaZJp+HIZsQD4a8dCPNZVrQJNZt6FFfE0M01IQSw KnjAmzp9om9CAfrTPyu2bnHXa9ktmU2zOeat267TKzSB8zw1/AlHDpf/sODd6uTi lTeInri1NNc2r2VS5mAUWwTUHOHPLPS2PTH+Dpd0vla1qcbUFArfFONgICH3VnYs kqL/Y5ZlhzVC+YXOUDdw+poTSYL/sxTYU+8OImSXbVrhAOT0xTlXX80fqjZJ+lvM 1edtWoZQcpQQ7hZNq919LOrd770e3hkfFHTogwLQ3ROADxGGpOCcsySPDS1Xl2bX b+7HAagYfYknzF2UyZjmc4zn3BtGYYeHkKAWfeuj3U6V5JV2wut/vTHaSgYt4Jue Efy3745ZOZGVcj0UJ6YhN7BNY/kpsfeaiTMcismkU0ywKaINY8rX2GjdX68xmGaa Cs//sGmMSbTNb7JjqdHWY5GJG+q6qUzSyPsSiNfv8F+EsPW/u5PEl/VEo9nl2uvm bXgDVs7M9codkftA8ma7 =LawE -----END PGP SIGNATURE----- . ========================================================================== Ubuntu Security Notice USN-3001-1 June 10, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. (CVE-2016-2117) Jann Horn discovered that eCryptfs improperly attempted to use the mmap() handler of a lower filesystem that did not implement one, causing a recursive page fault to occur. (CVE-2016-1583) Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB over wifi device drivers in the Linux kernel. (CVE-2016-3672) Andrey Konovalov discovered that the CDC Network Control Model USB driver in the Linux kernel did not cancel work events queued if a later error occurred, resulting in a use-after-free. (CVE-2016-4485) Kangjie Lu discovered an information leak in the routing netlink socket interface (rtnetlink) implementation in the Linux kernel. A local unprivileged attacker could use this to possibly gain administrative privileges on systems where InifiniBand related kernel modules are loaded. (CVE-2016-4581) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: linux-image-3.19.0-61-generic 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-generic-lpae 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-lowlatency 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-powerpc-e500mc 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-powerpc-smp 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-powerpc64-emb 3.19.0-61.69~14.04.1 linux-image-3.19.0-61-powerpc64-smp 3.19.0-61.69~14.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: http://www.ubuntu.com/usn/usn-3001-1 CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187, CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-3961, CVE-2016-4485, CVE-2016-4486, CVE-2016-4565, CVE-2016-4581 Package Information: https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-61.69~14.04.1 . It was discovered that the compression handling code in the Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel did not properly check for an integer overflow. (CVE-2014-9904) Kirill A

Trust: 2.97

sources: NVD: CVE-2016-3961 // JVNDB: JVNDB-2016-002112 // CNVD: CNVD-2016-02390 // VULMON: CVE-2016-3961 // PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 138270 // PACKETSTORM: 137696 // PACKETSTORM: 137416 // PACKETSTORM: 139673 // PACKETSTORM: 139678

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-02390

AFFECTED PRODUCTS

vendor:xenmodel:xenscope:lteversion:4.5.3

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:14.04

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:15.10

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:16.04

Trust: 1.0

vendor:xenmodel:xenscope:lteversion:4.5.x

Trust: 0.8

vendor:xenmodel:pvscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-02390 // JVNDB: JVNDB-2016-002112 // NVD: CVE-2016-3961

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-3961
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-3961
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2016-02390
value: LOW

Trust: 0.6

VULMON: CVE-2016-3961
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2016-3961
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2016-02390
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2016-3961
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-02390 // VULMON: CVE-2016-3961 // JVNDB: JVNDB-2016-002112 // NVD: CVE-2016-3961

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2016-002112 // NVD: CVE-2016-3961

THREAT TYPE

remote, local

Trust: 0.4

sources: PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 137416

TYPE

arbitrary

Trust: 0.5

sources: PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 138270 // PACKETSTORM: 137416

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-002112

PATCH

title:xsa174.patchurl:http://xenbits.xen.org/xsa/xsa174.patch

Trust: 0.8

title:XSA-174url:http://xenbits.xen.org/xsa/advisory-174.html

Trust: 0.8

title:Patch for XenPV Virtual Machine Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/74420

Trust: 0.6

title:Red Hat: CVE-2016-3961url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2016-3961

Trust: 0.1

title:Ubuntu Security Notice: linux vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3127-1

Trust: 0.1

title:Ubuntu Security Notice: linux-lts-trusty vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3127-2

Trust: 0.1

title:Ubuntu Security Notice: linux-ti-omap4 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3050-1

Trust: 0.1

title:Ubuntu Security Notice: linux vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3049-1

Trust: 0.1

title:Brocade Security Advisories: BSA-2017-204url:https://vulmon.com/vendoradvisory?qidtp=brocade_security_advisories&qid=426d0c0eff7642baadbe130aeadad5b8

Trust: 0.1

title:Ubuntu Security Notice: linux vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3006-1

Trust: 0.1

title:Ubuntu Security Notice: linux-lts-xenial vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3005-1

Trust: 0.1

title:Ubuntu Security Notice: linux-raspi2 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3007-1

Trust: 0.1

title:Ubuntu Security Notice: linux vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3003-1

Trust: 0.1

title:Ubuntu Security Notice: linux-lts-vivid vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3001-1

Trust: 0.1

title:Ubuntu Security Notice: linux-lts-wily vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3002-1

Trust: 0.1

title:Ubuntu Security Notice: linux-raspi2 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-3004-1

Trust: 0.1

title:Amazon Linux AMI: ALAS-2016-703url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2016-703

Trust: 0.1

title:Debian Security Advisories: DSA-3607-1 linux -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=130ea7817d6c997c442bd2ad39a2da75

Trust: 0.1

sources: CNVD: CNVD-2016-02390 // VULMON: CVE-2016-3961 // JVNDB: JVNDB-2016-002112

EXTERNAL IDS

db:NVDid:CVE-2016-3961

Trust: 3.3

db:SECTRACKid:1035569

Trust: 1.1

db:BIDid:86068

Trust: 1.1

db:JVNDBid:JVNDB-2016-002112

Trust: 0.8

db:OPENWALLid:OSS-SECURITY/2016/04/14/2

Trust: 0.6

db:CNVDid:CNVD-2016-02390

Trust: 0.6

db:VULMONid:CVE-2016-3961

Trust: 0.1

db:PACKETSTORMid:137422

Trust: 0.1

db:PACKETSTORMid:137421

Trust: 0.1

db:PACKETSTORMid:137419

Trust: 0.1

db:PACKETSTORMid:138270

Trust: 0.1

db:PACKETSTORMid:137696

Trust: 0.1

db:PACKETSTORMid:137416

Trust: 0.1

db:PACKETSTORMid:139673

Trust: 0.1

db:PACKETSTORMid:139678

Trust: 0.1

sources: CNVD: CNVD-2016-02390 // VULMON: CVE-2016-3961 // JVNDB: JVNDB-2016-002112 // PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 138270 // PACKETSTORM: 137696 // PACKETSTORM: 137416 // PACKETSTORM: 139673 // PACKETSTORM: 139678 // NVD: CVE-2016-3961

REFERENCES

url:http://www.ubuntu.com/usn/usn-3001-1

Trust: 1.2

url:http://www.ubuntu.com/usn/usn-3004-1

Trust: 1.2

url:http://www.ubuntu.com/usn/usn-3006-1

Trust: 1.2

url:http://www.ubuntu.com/usn/usn-3007-1

Trust: 1.2

url:http://www.ubuntu.com/usn/usn-3050-1

Trust: 1.2

url:http://www.debian.org/security/2016/dsa-3607

Trust: 1.1

url:http://www.securityfocus.com/bid/86068

Trust: 1.1

url:http://www.securitytracker.com/id/1035569

Trust: 1.1

url:http://www.ubuntu.com/usn/usn-3002-1

Trust: 1.1

url:http://www.ubuntu.com/usn/usn-3003-1

Trust: 1.1

url:http://www.ubuntu.com/usn/usn-3005-1

Trust: 1.1

url:http://www.ubuntu.com/usn/usn-3049-1

Trust: 1.1

url:http://xenbits.xen.org/xsa/advisory-174.html

Trust: 1.1

url:http://xenbits.xen.org/xsa/xsa174.patch

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-3961

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-3961

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2016-3961

Trust: 0.8

url:http://www.openwall.com/lists/oss-security/2016/04/14/2

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2016-2117

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-4486

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-4565

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-4485

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-1583

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-2187

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2016-4581

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2016-3955

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-3672

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2016-3951

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-8839

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-4558

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-4004

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-3134

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-4470

Trust: 0.2

url:http://www.ubuntu.com/usn/usn-3127-1

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2016-7042

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2014-9904

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3288

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/20.html

Trust: 0.1

url:https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-3961

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2016-3961

Trust: 0.1

url:https://usn.ubuntu.com/3127-1/

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1012.16

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux/4.4.0-24.43

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-raspi2/4.2.0-1031.41

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-5243

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1485.112

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1237

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-2186

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-2143

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-2184

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4569

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3138

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-2185

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3137

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3140

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3070

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4482

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3136

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-0821

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-3156

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7515

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-61.69~14.04.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-101.148~precise1

Trust: 0.1

url:http://www.ubuntu.com/usn/usn-3127-2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/linux/3.13.0-101.148

Trust: 0.1

sources: CNVD: CNVD-2016-02390 // VULMON: CVE-2016-3961 // JVNDB: JVNDB-2016-002112 // PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 138270 // PACKETSTORM: 137696 // PACKETSTORM: 137416 // PACKETSTORM: 139673 // PACKETSTORM: 139678 // NVD: CVE-2016-3961

CREDITS

Ubuntu

Trust: 0.7

sources: PACKETSTORM: 137422 // PACKETSTORM: 137421 // PACKETSTORM: 137419 // PACKETSTORM: 138270 // PACKETSTORM: 137416 // PACKETSTORM: 139673 // PACKETSTORM: 139678

SOURCES

db:CNVDid:CNVD-2016-02390
db:VULMONid:CVE-2016-3961
db:JVNDBid:JVNDB-2016-002112
db:PACKETSTORMid:137422
db:PACKETSTORMid:137421
db:PACKETSTORMid:137419
db:PACKETSTORMid:138270
db:PACKETSTORMid:137696
db:PACKETSTORMid:137416
db:PACKETSTORMid:139673
db:PACKETSTORMid:139678
db:NVDid:CVE-2016-3961

LAST UPDATE DATE

2024-12-20T21:50:38.278000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-02390date:2016-04-20T00:00:00
db:VULMONid:CVE-2016-3961date:2016-11-28T00:00:00
db:JVNDBid:JVNDB-2016-002112date:2016-04-20T00:00:00
db:NVDid:CVE-2016-3961date:2024-11-21T02:51:02.630

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-02390date:2016-04-20T00:00:00
db:VULMONid:CVE-2016-3961date:2016-04-15T00:00:00
db:JVNDBid:JVNDB-2016-002112date:2016-04-20T00:00:00
db:PACKETSTORMid:137422date:2016-06-10T06:09:00
db:PACKETSTORMid:137421date:2016-06-10T06:08:00
db:PACKETSTORMid:137419date:2016-06-10T06:06:00
db:PACKETSTORMid:138270date:2016-08-10T15:31:42
db:PACKETSTORMid:137696date:2016-06-28T15:46:11
db:PACKETSTORMid:137416date:2016-06-10T06:03:00
db:PACKETSTORMid:139673date:2016-11-11T14:29:32
db:PACKETSTORMid:139678date:2016-11-11T14:30:23
db:NVDid:CVE-2016-3961date:2016-04-15T14:59:14.050