CVE-2005-3809 Information

Description

The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information which triggers a null dereference.

Reference

http://marc.info/?l=linux-kernel&m=113269476105016&w=2 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.14.3 http://www.osvdb.org/24114

Share on: