CVE-2006-0038 Information
Description
Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3 when using \virtualization solutions\ such as OpenVZ allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.
Reference
http://secunia.com/advisories/19330 http://secunia.com/advisories/20671 http://secunia.com/advisories/20716 http://secunia.com/advisories/20914 http://secunia.com/advisories/21465 http://secunia.com/advisories/22417 http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm http://www.debian.org/security/2006/dsa-1097 http://www.debian.org/security/2006/dsa-1103 http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168 http://www.redhat.com/support/errata/RHSA-2006-0575.html http://www.securityfocus.com/bid/17178 http://www.ubuntu.com/usn/usn-302-1 http://www.vupen.com/english/advisories/2006/1046 http://www.vupen.com/english/advisories/2006/2554 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295 https://exchange.xforce.ibmcloud.com/vulnerabilities/25400 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10945
Share on: