Release date: 2010-06-23
Updated on: 2010-09-13
Affected Systems:
Linux kernel 2.6.x
Unaffected system:
Linux kernel 2.6.34
Description:
--------------------------------------------------------------------------------
Bugtraq id: 41077
Cve id: CVE-2010-2495
Linux Kernel is the Kernel used by open source Linux.
Drivers/net/pppol2tp in Linux Kernel L2TP implementation. the pppol2tp_xmit function in the c file does not verify some interface-related values. Remote attackers can trigger NULL pointer references by sending malicious L2TP packets, resulting in DOS.
<* Source: James Chapman (jchapman@katalix.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 607054
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = 3feec9095d12e311b7d4eb7fe7e5dfa75d4a72a5