[kernel-sec-discuss] r746 - active
Martin Pitt
mpitt at alioth.debian.org
Wed Apr 25 11:27:04 UTC 2007
Author: mpitt
Date: 2007-04-25 11:27:04 +0000 (Wed, 25 Apr 2007)
New Revision: 746
Modified:
active/CVE-2007-1357
Log:
Ubuntu details for CVE-2007-1357
Modified: active/CVE-2007-1357
===================================================================
--- active/CVE-2007-1357 2007-04-25 11:22:27 UTC (rev 745)
+++ active/CVE-2007-1357 2007-04-25 11:27:04 UTC (rev 746)
@@ -3,6 +3,10 @@
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=75559c167bddc1254db5bcff032ad5eed8bd6f4a
Description:
Ubuntu-Description:
+ Philipp Richter discovered that the AppleTalk protocol handler did
+ not sufficiently verify the length of packets. By sending a crafted
+ AppleTalk packet, a remote attacker could exploit this to crash the
+ kernel.
Notes:
dannf> commit msg says that the vulnerable code was added in 2.6.0-test5:
http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=7ab442d7e0a76402c12553ee256f756097cae2d2
@@ -14,6 +18,6 @@
2.6.18-etch-security: pending (2.6.18.dfsg.1-12etch1) [bugfix/appletalk-length-mismatch.patch, bugfix/appletalk-endianness-annotations.patch]
2.6.8-sarge-security: pending (2.6.8-16sarge7) [appletalk-length-mismatch.dpatch, appletalk-endianness-annotations.dpatch]
2.4.27-sarge-security: N/A
-2.6.12-breezy-security:
-2.6.15-dapper-security:
-2.6.17-edgy-security:
+2.6.15-dapper-security: needed
+2.6.17-edgy-security: needed
+2.6.20-feisty-security: needed
More information about the kernel-sec-discuss
mailing list