The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.
References
Configurations
History
No history.
Information
Published : 2011-01-03 20:00
Updated : 2023-02-13 04:27
NVD link : CVE-2010-3873
Mitre link : CVE-2010-3873
CVE.ORG link : CVE-2010-3873
JSON object : View
Products Affected
opensuse
- opensuse
debian
- debian_linux
suse
- linux_enterprise_server
linux
- linux_kernel
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer