CVE Vulnerabilities

CVE-2002-1912

NULL Pointer Dereference

Published: Dec 31, 2002 | Modified: Dec 28, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Emr5000 Skystream 1.16 (including) 1.16 (including)
Emr5000 Skystream 1.17 (including) 1.17 (including)
Emr5000 Skystream 1.18 (including) 1.18 (including)

Potential Mitigations

References