Iproute2 Project Iproute2 vulnerabilities
2 known vulnerabilities affecting iproute2_project/iproute2.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2019-20795MEDIUMCVSS 4.4fixed in 5.1.02020-05-09
CVE-2019-20795 [MEDIUM] CWE-416 CVE-2019-20795: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
nvdosv
CVE-2012-1088LOWCVSS 3.3≤ 3.2.0v3.0.0+1 more2014-02-15
CVE-2012-1088 [LOW] CWE-59 CVE-2012-1088: iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temp
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
nvdosv