summaryrefslogtreecommitdiffstats
path: root/active
diff options
context:
space:
mode:
authorMartin Pitt <mpitt@debian.org>2007-04-25 11:44:59 +0000
committerMartin Pitt <mpitt@debian.org>2007-04-25 11:44:59 +0000
commitc8183f089506328e211d16dcb3ee75ff6c76e01c (patch)
treed812761b0b35b9940cb783a6234cc7d2c3d6ead8 /active
parent999373cdccb9832b16abe9b2d5b6f76efc7a621a (diff)
add CVE-2007-1496
git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@749 e094ebfe-e918-0410-adfb-c712417f3574
Diffstat (limited to 'active')
-rw-r--r--active/CVE-2007-149623
1 files changed, 23 insertions, 0 deletions
diff --git a/active/CVE-2007-1496 b/active/CVE-2007-1496
new file mode 100644
index 00000000..716d7607
--- /dev/null
+++ b/active/CVE-2007-1496
@@ -0,0 +1,23 @@
+Candidate: CVE-2007-1496
+References:
+ http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dd16704eba171b32ef0cded3a4f562b33b911066
+Description:
+ nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows
+ attackers to cause a denial of service (crash) via unspecified
+ vectors involving the (1) nfulnl_recv_config function, (2) using
+ "multiple packets per netlink message", and (3) bridged packets,
+ which trigger a NULL pointer dereference.
+Ubuntu-Description:
+ A Denial of Service vulnerability was discovered in the
+ nfnetlink_log() netfilter function. A remote attacker could exploit
+ this to trigger a kernel crash.
+Notes:
+Bugs:
+upstream: released (2.6.20.3)
+linux-2.6:
+2.6.18-etch-security:
+2.6.8-sarge-security:
+2.4.27-sarge-security:
+2.6.15-dapper-security: needed
+2.6.17-edgy-security: needed
+2.6.20-feisty-security: needed

© 2014-2024 Faster IT GmbH | imprint | privacy policy