Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 17-06-2008, 05:13 PM   #1 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Post Linux Kernel "pppol2tp_recvmsg()" Memory Corruption Vulnerability


Quote:
Linux Kernel "pppol2tp_recvmsg()" Memory Corruption Vulnerability
Secunia Advisory: SA30719 Release Date: 2008-06-16
Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Workaround
OS:Linux Kernel 2.6.x







Description:
A vulnerability has been reported in the Linux Kernel, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a boundary error in the "pppol2tp_recvmsg()" function and can potentially be exploited to corrupt kernel memory via a specially crafted PPP over L2TP packet.

The vulnerability is reported in 2.6.x versions prior to 2.6.26-rc6.

Solution:
Use PPP over L2TP in trusted networks only.

Fixed in version 2.6.26-rc6.

Provided and/or discovered by:
The vendor credits Ilja of Netric.

Original Advisory:
http://kernel.org/pub/linux/kernel/v...Log-2.6.26-rc6

http://git.kernel.org/?p=linux/kernel...707a50c7598a83820077393f8823ab791abf8
http://secunia.com/advisories/30719/
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 17-06-2008, 05:23 PM   #2 (permalink)
The Smaller Bang
 
MetalheadGautham's Avatar
 
Join Date: Sep 2007
Location: Gautham City
Posts: 7,492
Default Re: Linux Kernel "pppol2tp_recvmsg()" Memory Corruption Vulnerability

DoS can't happen if you set your firewall up properly for home systems.
I use KMyFirewall, a GUI for IPTables, and I configured it so that it always limits the number of incomming connections, and at most times even disabling them.
__________________
http://TheSmallerBang.wordpress.com
eMachines E725 - T4400 2.2GHz, 1GB, 160GB
Nokia 5130XM * T-Sonic 610 2GB
Nokia 2323C * Samsung Galaxy Y
Apple iPad 2 16GB WiFi
MetalheadGautham is offline  
Old 17-06-2008, 09:38 PM   #3 (permalink)
In The Zone
 
unni's Avatar
 
Join Date: Mar 2006
Location: Thiruvananthapuram (Now in Bengaluru)
Posts: 386
Default Re: Linux Kernel "pppol2tp_recvmsg()" Memory Corruption Vulnerability

The thread title scared me. Thanks for sharing the info.
unni is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
"Could not find kernel image" error sam_1710 Open Source 13 17-03-2007 06:34 PM
"Kernel unable to sync" sam_1710 Open Source 8 04-11-2006 09:34 PM
Explorer.exe - Application Error The instruction at "0x01604213" referenced memory at rollcage Software Q&A 1 13-06-2006 07:11 PM
REQUEST:"Best Brand" Memory Card for Nokia 6630/Mumbai/Price maximus999 Mobiles and Tablets 8 23-02-2006 04:14 AM
"Unable to initialize memory stream" acerishabh QnA (read only) 3 13-07-2005 04:42 PM

 
Latest Threads
- by abhidev
- by chris
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 05:54 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2