Secunia Logo
 
CVE Reference: CVE-2005-2709
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2709

Description:
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/23040

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-219-1

ST
  1015434

SAID
  Secunia Advisory: SA19369
  Secunia Advisory: SA19374
  Secunia Advisory: SA18684
  Secunia Advisory: SA18562
  Secunia Advisory: SA18510
  Secunia Advisory: SA17648
  Secunia Advisory: SA17541
  Secunia Advisory: SA17504

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0190.html
  http://www.redhat.com/support/errata/RHSA-2006-0191.html
  http://www.redhat.com/support/errata/RHSA-2006-0101.html
  http://www.redhat.com/support/errata/RHSA-2006-0140.html

OSVDB
  20676

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059

FEDORA
  http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded

DEBIAN
  http://www.debian.org/security/2006/dsa-1018
  http://www.debian.org/security/2006/dsa-1017

CONFIRM
  http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.14.1

BID
  15365


Return to the previous page.