Release date:
Updated on:
Affected Systems:
Debian Linux 5.0 x
Linux kernel 2.6.0-2.6.36
Unaffected system:
Linux kernel 2.6.37-rc2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45055
Cve id: CVE-2010-4164
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel has a vulnerability in implementation. Remote attackers can exploit this vulnerability to cause Kernel crash and cause DOS.
This vulnerability occurs because "x25_parse_facilities ()" does not properly process user input. Reducing the remaining length can cause underflow when parsing malformed X.25 protocols. Because the length is an unsigned integer, this will cause a loop until the kernel crashes.
<* Source: Dan Rosenberg
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.debian.org/security/