Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4567

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2007-4567
Last Modified 19 Mar 2012 12:00:00
Published 20 Dec 2007 07:46:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-4567

Summary

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.

Vulnerable Systems

Operating System

  • Linux Kernel 2.2.27

  • Linux Kernel 2.4.36

  • Linux Kernel 2.4.36.1

  • Linux Kernel 2.4.36.2

  • Linux Kernel 2.4.36.3

  • Linux Kernel 2.4.36.4

  • Linux Kernel 2.4.36.5

  • Linux Kernel 2.4.36.6

  • Linux Kernel 2.6

  • Linux Kernel 2.6.18

  • Linux Kernel 2.6.19.4

  • Linux Kernel 2.6.19.5

  • Linux Kernel 2.6.19.6

  • Linux Kernel 2.6.19.7

  • Linux Kernel 2.6.20.16

  • Linux Kernel 2.6.20.17

  • Linux Kernel 2.6.20.18

  • Linux Kernel 2.6.20.19

  • Linux Kernel 2.6.20.20

  • Linux Kernel 2.6.20.21

  • Linux Kernel 2.6.21.5

  • Linux Kernel 2.6.21.6

  • Linux Kernel 2.6.21.7


References

REDHAT - RHSA-2010:0095

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=548641

XF - linux-kernel-ipv6-dos(39171)

UBUNTU - USN-558-1

UBUNTU - USN-574-1

BID - 26943

REDHAT - RHSA-2010:0053

REDHAT - RHSA-2010:0019

SECUNIA - 38015

SECUNIA - 28706

SECUNIA - 28170

SECUNIA - 25505

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e76b2b2567b83448c2ee85a896433b96150c92e6

CONFIRM - http://bugzilla.kernel.org/show_bug.cgi?id=8450


Last Updated: 27 May 2016 10:57:29