Description: A vulnerability with unknown impact has been reported in the Linux Kernel.
The vulnerability is caused due to a boundary error within the "isdn_net_setcfg()" function in drivers/isdn/i4l/isdn_net.c when processing IOCTL configuration requests sent to the ISDN pseudo device (/dev/isdnctrl). This can be exploited to cause a buffer overflow via a specially crafted IIOCNETSCF IOCTL request.
Successful exploitation requires write access to /dev/isdnctrl.
The vulnerability is reported in version 2.6.23. Other versions may also be affected.
Solution: Update to version 2.4.35.5 or 2.6.23.10.
Provided and/or discovered by: Venustech AD-LAB
Changelog: 2007-12-17: Updated "Solution" section. Added "Linux Kernel 2.4.x" to the list of affected products.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.