blob: 9bae0a050b98b1d17836513d37dc1aa877deaf27 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
|
Candidate: CVE-2007-6282
Description:
The IPsec implementation in Linux kernel before 2.6.25 allows remote
routers to cause a denial of service (crash) via a fragmented ESP packet in
which the first fragment does not contain the entire ESP header and IV.
References:
Ubuntu-Description:
Notes:
kees> linux-2.6: 920fc941a9617f95ccb283037fe6f8a38d95bb69
Bugs:
upstream:
linux-2.6:
2.6.18-etch-security: released (2.6.18.dfsg.1-22etch1) [bugfix/esp-iv-in-linear-part-of-skb.patch]
2.6.24-etch-security: released (2.6.24-6~etchnhalf.4) [bugfix/esp-iv-in-linear-part-of-skb.patch]
2.6.26-lenny-security: N/A
2.6.15-dapper-security: pending
2.6.20-feisty-security: pending
2.6.22-gutsy-security: pending
2.6.24-hardy-security: pending
|