Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Multiple Linux Vendor IP Options Vulnerability

A vulnerability in the Linux Kernel's IPv4 option processing may allow a remote user to crash the system.

The vulnerability is the result of the kernel freeing a socket buffer when it shouldn't while sending an ICMP Parameter Problem error message in response to an IP packet with a malformed IP option. This results in the buffer being freed twice and in memory corruption.

Of the Debian Linux 2.1 supported architectures only the SPARC one is vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus