| 1 |
Candidate: CVE-2006-4623
|
| 2 |
References:
|
| 3 |
http://lkml.org/lkml/2006/8/20/278
|
| 4 |
Description:
|
| 5 |
The Unidirectional Lightweight Encapsulation (ULE) decapsulation
|
| 6 |
component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel
|
| 7 |
2.6.17.8 allows remote attackers to cause a denial of service (crash)
|
| 8 |
via an SNDU length of 0 in a ULE packet.
|
| 9 |
Ubuntu-Description:
|
| 10 |
A flaw was discovered in dvb ULE decapsulation. A remote attacker could
|
| 11 |
send a specially crafted message and cause a denial of service.
|
| 12 |
Notes:
|
| 13 |
mpitt> Questionable -- rather than fixing the kernel to not send out
|
| 14 |
invalid ULE packets, it should be fixed to not crash upon
|
| 15 |
receiving one.
|
| 16 |
dannf> I noticed that a different, and much larger patch went into 2.6.18
|
| 17 |
that conflicts with the one provided by the original reporter (which
|
| 18 |
went into 2.6.17.y). I asked the original reporter if that patch also
|
| 19 |
fixed the issue. Ang Way replied:
|
| 20 |
"Yes, it is fixed in 2.6.18 and later even though the patch is
|
| 21 |
different. Their fix is more elegant."
|
| 22 |
So, marking etch N/A
|
| 23 |
Bugs:
|
| 24 |
upstream: released (2.6.18)
|
| 25 |
linux-2.6: released (2.6.18-1)
|
| 26 |
2.6.18-etch-security: N/A
|
| 27 |
2.6.8-sarge-security: released (2.6.8-16sarge7) [dvb-core-handle-0-length-ule-sndu.dpatch]
|
| 28 |
2.4.27-sarge-security: N/A
|
| 29 |
2.6.15-dapper-security: released (2.6.15-28.57)
|
| 30 |
2.6.17-edgy: released (2.6.17.1-10.34)
|
| 31 |
2.6.20-feisty-security: N/A
|