CVE-2007-5087 Information

Description

The ATM module in the Linux kernel before 2.4.35.3 when CLIP support is enabled allows local users to cause a denial of service (kernel panic) by reading /proc/net/atm/arp before the CLIP module has been loaded.

Reference

http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.35.y.git;a=commitdiff;h=b7ae15e7707050baafe5a35e3d4f2d175197d222 http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35.3 http://lwn.net/Articles/251162/ http://osvdb.org/39237 http://www.securityfocus.com/bid/25798 http://www.vupen.com/english/advisories/2007/3246

Share on: