blob: 10581fb16b429a07a4d4a0a94e15710a79b54b26 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
|
Candidate: CVE-2007-6282
Description:
The IPsec implementation in Linux kernel before 2.6.25 allows remote
routers to cause a denial of service (crash) via a fragmented ESP packet in
which the first fragment does not contain the entire ESP header and IV.
References:
Ubuntu-Description:
Notes:
kees> linux-2.6: 920fc941a9617f95ccb283037fe6f8a38d95bb69
Bugs:
upstream: released (2.6.25)
linux-2.6: released (2.6.25-1)
2.6.18-etch-security: released (2.6.18.dfsg.1-22etch1) [bugfix/esp-iv-in-linear-part-of-skb.patch]
2.6.24-etch-security: released (2.6.24-6~etchnhalf.4) [bugfix/esp-iv-in-linear-part-of-skb.patch]
2.6.26-lenny-security: N/A
2.6.15-dapper-security: released (2.6.15-52.69)
2.6.20-feisty-security: released (2.6.20-17.37)
2.6.22-gutsy-security: released (2.6.22-15.56)
2.6.24-hardy-security: released (2.6.24-19.36)
|