Total vulnerabilities in the database
The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.
Software | From | Fixed in |
---|---|---|
novell / suse_linux_enterprise_server | 10.0-sp4 | 10.0-sp4.x |
linux / linux_kernel | 2.6.38-rc7 | 2.6.38-rc7.x |
linux / linux_kernel | 2.6.38-rc6 | 2.6.38-rc6.x |
linux / linux_kernel | 2.6.38-rc4 | 2.6.38-rc4.x |
linux / linux_kernel | 2.6.38.3 | 2.6.38.3.x |
linux / linux_kernel | - | 2.6.38.8.x |
linux / linux_kernel | 2.6.38-rc3 | 2.6.38-rc3.x |
linux / linux_kernel | 2.6.38-rc5 | 2.6.38-rc5.x |
linux / linux_kernel | 2.6.38-rc2 | 2.6.38-rc2.x |
linux / linux_kernel | 2.6.38.6 | 2.6.38.6.x |
linux / linux_kernel | 2.6.38.1 | 2.6.38.1.x |
linux / linux_kernel | 2.6.38-rc1 | 2.6.38-rc1.x |
linux / linux_kernel | 2.6.38.5 | 2.6.38.5.x |
linux / linux_kernel | 2.6.38.2 | 2.6.38.2.x |
linux / linux_kernel | 2.6.38 | 2.6.38.x |
linux / linux_kernel | 2.6.38-rc8 | 2.6.38-rc8.x |
linux / linux_kernel | 2.6.38.4 | 2.6.38.4.x |
linux / linux_kernel | 2.6.38.7 | 2.6.38.7.x |