Denial of service - CVE-2016-1433

 

Denial of service - CVE-2016-1433

Published: September 16, 2016


Vulnerability identifier: #VU484
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-1433
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote unauthenticated user to cause limited denial of service conditions on the target system.
The weakness is caused by logic error in OSPFv3 processing. Handling of specially crafted OSPFv3 packet leads to the process reloading and causes denial of service.
Successful exploitation of the vulnerability allows a malicious user to trigger limited DoS conditions on the vulnerable system.

How to mitigate CVE-2016-1433


Sources