[kernel-sec-discuss] r749 - active

Martin Pitt mpitt at alioth.debian.org
Wed Apr 25 11:45:00 UTC 2007


Author: mpitt
Date: 2007-04-25 11:44:59 +0000 (Wed, 25 Apr 2007)
New Revision: 749

Added:
   active/CVE-2007-1496
Log:
add CVE-2007-1496

Added: active/CVE-2007-1496
===================================================================
--- active/CVE-2007-1496	2007-04-25 11:37:08 UTC (rev 748)
+++ active/CVE-2007-1496	2007-04-25 11:44:59 UTC (rev 749)
@@ -0,0 +1,23 @@
+Candidate: CVE-2007-1496
+References:
+ http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dd16704eba171b32ef0cded3a4f562b33b911066
+Description: 
+ nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows
+ attackers to cause a denial of service (crash) via unspecified
+ vectors involving the (1) nfulnl_recv_config function, (2) using
+ "multiple packets per netlink message", and (3) bridged packets,
+ which trigger a NULL pointer dereference.
+Ubuntu-Description: 
+ A Denial of Service vulnerability was discovered in the
+ nfnetlink_log() netfilter function. A remote attacker could exploit
+ this to trigger a kernel crash.
+Notes: 
+Bugs: 
+upstream: released (2.6.20.3)
+linux-2.6: 
+2.6.18-etch-security: 
+2.6.8-sarge-security: 
+2.4.27-sarge-security: 
+2.6.15-dapper-security: needed
+2.6.17-edgy-security: needed
+2.6.20-feisty-security: needed




More information about the kernel-sec-discuss mailing list