Computer Security
[EN] securityvulns.ru
no-pyccku



Linux multiple security vulnerabilities
Published:29.05.2008
Source:BUGTRAQ
SecurityVulns ID:9029
Type:remote
Level:5/10
Description:Memory leak in IPv6 over IPv4 tunnels, mmap DoS on the SPARC architecture, DoS on amd64 architecture, DoS with hrtimer integer overflow on 64bit architectures.
Affected:LINUX : kernel 2.6
CVE:CVE-2008-2137
 CVE-2008-2136 (Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.)
 CVE-2008-1615
 CVE-2007-6712 (Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users to cause a denial of service (infinite loop) via a timer with a large expiry value, which causes the timer to always be expired.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 1588-1] New Linux 2.6.18 packages fix several vulnerabilities (29.05.2008)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru