Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2495

Опубликовано: 16 мар. 2010
Источник: redhat
CVSS2: 7.8

Описание

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.

Отчет

This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not backport the upstream commit ffcebb16 that introduced this vulnerability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-252->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=607054kernel: l2tp: Fix oops in pppol2tp_xmit

7.8 High

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.

nvd
больше 15 лет назад

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.

debian
больше 15 лет назад

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP imple ...

github
больше 3 лет назад

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.

suse-cvrf
почти 14 лет назад

Security update for Kernel

7.8 High

CVSS2