The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Umip | Linux-ipv6 | 0.4 (including) | 0.4 (including) |