SB2009040801 - Integer overflow in Linux kernel netrom
Published: April 8, 2009
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2009-1265)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to integer overflow within the x25_sendmsg() function in net/x25/af_x25.c, within the rose_sendmsg() function in net/rose/af_rose.c, within the nr_sendmsg() function in net/netrom/af_netrom.c. A remote non-authenticated attacker can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- http://bugzilla.kernel.org/show_bug.cgi?id=10423
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=83e0bbcbe2145f160fbaa109b0439dae7f4a38a9
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html
- http://osvdb.org/53571
- http://osvdb.org/53630
- http://osvdb.org/53631
- http://secunia.com/advisories/34981
- http://secunia.com/advisories/35011
- http://secunia.com/advisories/35121
- http://secunia.com/advisories/35185
- http://secunia.com/advisories/35387
- http://secunia.com/advisories/35390
- http://secunia.com/advisories/35394
- http://secunia.com/advisories/35656
- http://www.debian.org/security/2009/dsa-1787
- http://www.debian.org/security/2009/dsa-1794
- http://www.debian.org/security/2009/dsa-1800
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:119
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:135
- http://www.openwall.com/lists/oss-security/2009/04/08/2
- http://www.securityfocus.com/bid/34654
- http://www.ubuntu.com/usn/usn-793-1