CVE-2007-1861 Information
Description
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies which trigger infinite recursion and a stack overflow.
Reference
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.8 http://secunia.com/advisories/25030 http://secunia.com/advisories/25083 http://secunia.com/advisories/25228 http://secunia.com/advisories/25288 http://secunia.com/advisories/25691 http://secunia.com/advisories/25961 http://secunia.com/advisories/26133 http://secunia.com/advisories/26139 http://secunia.com/advisories/26620 http://www.debian.org/security/2007/dsa-1289 http://www.mandriva.com/security/advisories?name=MDKSA-2007:171 http://www.novell.com/linux/security/advisories/2007_43_kernel.html http://www.redhat.com/support/errata/RHSA-2007-0347.html http://www.securityfocus.com/archive/1/467939/30/6690/threaded http://www.securityfocus.com/archive/1/471457 http://www.securityfocus.com/bid/23677 http://www.ubuntu.com/usn/usn-486-1 http://www.ubuntu.com/usn/usn-489-1 http://www.vupen.com/english/advisories/2007/1595 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=237913 https://exchange.xforce.ibmcloud.com/vulnerabilities/34014 https://issues.rpath.com/browse/RPL-1309 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A11616
Share on: