CERT-In Vulnerability Note
CIVN-2007-0145
Multiple Vulnerabilities in Linux Kernel
Original Issue Date:November 26, 2007
Severity Rating: MEDIUM
Systems Affected
Linux Kernel versions prior to 2.6.23.8
Overview
Multiple vulnerabilities have been reported in Linux Kernel which could be exploited by local/remote attacker to cause a denial of service on the affected system.
Description
1. wait_task_stopped Denial of Service vulnerability in Linux Kernel
(
CVE-2007-5500
)
A vulnerability has been reported in Linux kernel due to an error in "wait_task_stopped " [kernel/exit.c] function when it fails to check if a process was "not dead" while handling certain process-exit conditions. This vulnerability could be exploited by a local attacker to cause a system crash via unspecified vectors.
2. Linux kernel tcp_sacktag_write_queue denial of service Vulnerability
(
CVE-2007-5501
)
A vulnerability has been reported in Linux kernel due to an NULL-pointer dereference error within the "tcp_sacktag_write_queue " [net/ipv4/tcp_input.c] function while processing ACK packets. This vulnerability could be exploited by remote attackers to cause denial of service via specially crafted ACK packets that trigger a NULL pointer dereference.
3. Buffer overflow vulnerabilty in Linux kernel
(
CVE-2007-6063CWE-119
)
A vulnerability has been reported in Linux kernel due to a design error in the "isdn_net_setcfg"[isdn_net.c] function. This vulnerability could be exploited by local attackers to cause unknown impact via a crafted argument to the isdn_ioctl function.
Solution
Upgrade to Linux Kernel versions as provided by vendor.
http://www.kernel.org
Vendor Information
Kernel
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.8
http://bugzilla.kernel.org/show_bug.cgi?id=9416
References
Secunia
http://secunia.com/advisories/27664/
FrSirt
http://www.frsirt.com/english/advisories/2007/3902
Securityfocus
http://www.securityfocus.com/bid/26477/info
CVE Name
CVE-2007-5500
CVE-2007-5501
CVE-2007-6063
CWE Name
CWE-119
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|