CVE-2010-0751
published 2010-04-06CVE-2010-0751: The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.94%
89.2th percentile
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnids | < libnids 1.23-1.2 (bookworm) | libnids 1.23-1.2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libnids_project | libnids | < 1.24 | 1.24 |
| libnids_project | libnids | >= 0 < 1.23-1.2 | 1.23-1.2 |
| libnids_project | libnids | >= 0 < 1.23-1.2 | 1.23-1.2 |
| libnids_project | libnids | >= 0 < 1.23-1.2 | 1.23-1.2 |
| libnids_project | libnids | >= 0 < 1.23-1.2 | 1.23-1.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-0751: libnids - The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsni...
vendor_debian·2010·CVSS 5.0
CVE-2010-0751 [MEDIUM] CVE-2010-0751: libnids - The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsni...
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
Scope: local
bookworm: resolved (fixed in 1.23-1.2)
bullseye: resolved (fixed in 1.23-1.2)
forky: resolved (fixed in 1.23-1.2)
sid: resolved (fixed in 1.23-1.2)
trixie: resolved (fixed in 1.23-1.2)
GHSA
GHSA-gpv2-xp96-53xg: The ip_evictor function in ip_fragment
ghsa_unreviewed·2022-05-02
CVE-2010-0751 [MEDIUM] CWE-476 GHSA-gpv2-xp96-53xg: The ip_evictor function in ip_fragment
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
OSV
CVE-2010-0751: The ip_evictor function in ip_fragment
osv·2010-04-06·CVSS 5.0
CVE-2010-0751 [MEDIUM] CVE-2010-0751: The ip_evictor function in ip_fragment
The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://freefr.dl.sourceforge.net/project/libnids/libnids/1.24/libnids-1.24.releasenotes.txthttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038375.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038388.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038410.htmlhttp://secunia.com/advisories/39225http://secunia.com/advisories/39249http://www.securityfocus.com/bid/39142http://www.vupen.com/english/advisories/2010/0777http://www.vupen.com/english/advisories/2010/0791http://xorl.wordpress.com/2010/04/04/libnids-ip-fragmentation-remote-null-pointer-dereference/https://exchange.xforce.ibmcloud.com/vulnerabilities/57428http://freefr.dl.sourceforge.net/project/libnids/libnids/1.24/libnids-1.24.releasenotes.txthttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038375.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038388.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038410.htmlhttp://secunia.com/advisories/39225http://secunia.com/advisories/39249http://www.securityfocus.com/bid/39142http://www.vupen.com/english/advisories/2010/0777http://www.vupen.com/english/advisories/2010/0791http://xorl.wordpress.com/2010/04/04/libnids-ip-fragmentation-remote-null-pointer-dereference/https://exchange.xforce.ibmcloud.com/vulnerabilities/57428
2010-04-06
Published