CVE-2020-14305
published 2020-12-02CVE-2020-14305: An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port…
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
5.11%
91.4th percentile
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.12.6-1 (bookworm) | linux 4.12.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.11.12 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2020-14305: Voice Over IP H.323
vendor_android·2021-06-01·CVSS 8.1
CVE-2020-14305 [HIGH] CVE-2020-14305: Voice Over IP H.323
Android Security Bulletin 2021-06-01
CVE: CVE-2020-14305
Severity: HIGH
Type: EoP
Component: Voice Over IP H.323
References: A-174904512
Upstream kernel
Red Hat
kernel: memory corruption in Voice over IP nf_conntrack_h323 module
vendor_redhat·2020-06-09·CVSS 8.1
CVE-2020-14305 [HIGH] CWE-787 kernel: memory corruption in Voice over IP nf_conntrack_h323 module
kernel: memory corruption in Voice over IP nf_conntrack_h323 module
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av
Debian
CVE-2020-14305: linux - An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Ove...
vendor_debian·2020·CVSS 8.1
CVE-2020-14305 [HIGH] CVE-2020-14305: linux - An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Ove...
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
GHSA
GHSA-44qh-vx3p-466m: An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H
ghsa_unreviewed·2022-05-24
CVE-2020-14305 [CRITICAL] CWE-787 GHSA-44qh-vx3p-466m: An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
CVE-2020-14305: In nf_conntrack_helper_q931 of nf_conntrack_h323_main
osv·2021-06-01
CVE-2020-14305 CVE-2020-14305: In nf_conntrack_helper_q931 of nf_conntrack_h323_main
In nf_conntrack_helper_q931 of nf_conntrack_h323_main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
OSV
CVE-2020-14305: An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H
osv·2020-12-02·CVSS 8.1
CVE-2020-14305 [HIGH] CVE-2020-14305: An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
No detection rules found.
No public exploits indexed.
https://bugs.openvz.org/browse/OVZ-7188https://bugzilla.redhat.com/show_bug.cgi?id=1850716https://patchwork.ozlabs.org/project/netfilter-devel/patch/c2385b5c-309c-cc64-2e10-a0ef62897502%40virtuozzo.com/https://security.netapp.com/advisory/ntap-20201210-0004/https://bugs.openvz.org/browse/OVZ-7188https://bugzilla.redhat.com/show_bug.cgi?id=1850716https://patchwork.ozlabs.org/project/netfilter-devel/patch/c2385b5c-309c-cc64-2e10-a0ef62897502%40virtuozzo.com/https://security.netapp.com/advisory/ntap-20201210-0004/
2020-12-02
Published