Secunia Logo
 
CVE Reference: CVE-2007-1861
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1861

Description:
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/34014

UBUNTU
  http://www.ubuntu.com/usn/usn-489-1
  http://www.ubuntu.com/usn/usn-486-1

SUSE
  http://www.novell.com/linux/security/advisories/2007_43_kernel.html

SAID
  Secunia Advisory: SA25961
  Secunia Advisory: SA25691
  Secunia Advisory: SA25288
  Secunia Advisory: SA25228
  Secunia Advisory: SA25083
  Secunia Advisory: SA25030
  Secunia Advisory: SA26133
  Secunia Advisory: SA26139
  Secunia Advisory: SA26620

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0347.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2007:171

DEBIAN
  http://www.debian.org/security/2007/dsa-1289

CONFIRM
  http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.8

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/467939/30/6690/threaded
  http://www.securityfocus.com/archive/1/471457

BID
  23677


Return to the previous page.