<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CompuWorld &#187; linux bugs</title>
	<atom:link href="http://www.nofullstop.com/category/bugs-found/linux-bugs-bugs-found/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nofullstop.com</link>
	<description>The Genius Inside You Is Still Sleeping</description>
	<lastBuildDate>Thu, 09 Sep 2010 17:25:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Linux Kernel IPv6 Sockets DoS Vulnerability</title>
		<link>http://www.nofullstop.com/2007/03/23/linux-kernel-ipv6-sockets-dos-vulnerability/</link>
		<comments>http://www.nofullstop.com/2007/03/23/linux-kernel-ipv6-sockets-dos-vulnerability/#comments</comments>
		<pubDate>Fri, 23 Mar 2007 15:30:00 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[bugs found]]></category>
		<category><![CDATA[linux bugs]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/2007/03/23/linux-kernel-ipv6-sockets-dos-vulnerability/</guid>
		<description><![CDATA[A kernel vulnerability has been found today by Masayuki Nakagawa, which can be exploited by local attackers to cause a denial of service (DoS) attack. Affected Software Linux Kernel versions 2.6.x Description A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This issue [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify">A kernel vulnerability <a href="http://www.frsirt.com/english/advisories/2007/1084" target="_blank">has been found today</a> by <span class="blsp-spelling-error">Masayuki</span> <span class="blsp-spelling-error">Nakagawa</span>, which can be exploited by local attackers to cause a <a href="http://en.wikipedia.org/wiki/Denial-of-service_attack">denial of service (<span class="blsp-spelling-error">DoS</span>)</a> attack.</p>
<p><span style="font-weight: bold">Affected Software</span><br />
Linux Kernel versions 2.6.x</p>
<p><span style="font-weight: bold">Description</span></p>
<p style="text-align: justify">A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This issue is due to an error in the <span style="font-weight: bold">&#8220;<span class="blsp-spelling-error">tcp</span>_v6_syn_<span class="blsp-spelling-error">recv</span>_soc()&#8221; [net/<span class="blsp-spelling-error">ipv</span>6/<span class="blsp-spelling-error">tcp</span>_<span class="blsp-spelling-error">ipv</span>6.c]</span> function where the <span class="blsp-spelling-error">IPv</span>6 flow list <span style="font-weight: bold">(<span class="blsp-spelling-error">ipv</span>6_fl_<span class="blsp-spelling-error">socklist</span>)</span> is shared with child sockets, which could be exploited by malicious users to crash an affected system by manipulating listening <span class="blsp-spelling-error">IPv</span>6 <span class="blsp-spelling-error">TCP</span> sockets.</p>
<p style="text-align: justify">This issue has been rated as low risk and can only be exploited locally and <span style="font-weight: bold">not</span> remotely.</p>
<p><span style="font-weight: bold">Workaround Available</span></p>
<p style="text-align: justify">Apply patch :<br />
<a href="http://www.frsirt.com/english/solution-2007-1084-1.php">http://www.marc.info/?l=linux-netdev&amp;m=117406721731891</a></p>
<p style="text-align: justify">References for this kernel vulnerability can be found <a href="http://www.frsirt.com/english/advisories/2007/1084" target="_blank">here</a> and <a href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233478" target="_blank">here</a>.</p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/linux-bugs/" title="linux bugs" rel="tag">linux bugs</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2007/03/23/linux-kernel-ipv6-sockets-dos-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.404 seconds -->
<!-- Cached page served by WP-Cache -->
