CVE-2005-3848

Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."
References
Link Resource
http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
http://marc.info/?l=linux-kernel&m=112431016816937&w=2
http://marc.info/?l=linux-kernel&m=112439084918917&w=2
http://marc.info/?l=linux-kernel&m=112508479212728&w=2
http://secunia.com/advisories/18203
http://secunia.com/advisories/18510
http://secunia.com/advisories/18562
http://secunia.com/advisories/19038
http://secunia.com/advisories/19369
http://secunia.com/advisories/19374
http://www.debian.org/security/2006/dsa-1017
http://www.debian.org/security/2006/dsa-1018
http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git%3Ba=blob%3Bh=1cf41a8a8db3080c9a9243e77c5c447c8e694f87%3Bhb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd%3Bf=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb94c62c252796f42bb83fe40960d12f3ea5a82a
http://www.mandriva.com/security/advisories?name=MDKSA-2006:072
http://www.redhat.com/support/errata/RHSA-2006-0101.html
http://www.redhat.com/support/errata/RHSA-2006-0140.html
http://www.securityfocus.com/bid/16044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11346
https://usn.ubuntu.com/231-1/
http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
http://marc.info/?l=linux-kernel&m=112431016816937&w=2
http://marc.info/?l=linux-kernel&m=112439084918917&w=2
http://marc.info/?l=linux-kernel&m=112508479212728&w=2
http://secunia.com/advisories/18203
http://secunia.com/advisories/18510
http://secunia.com/advisories/18562
http://secunia.com/advisories/19038
http://secunia.com/advisories/19369
http://secunia.com/advisories/19374
http://www.debian.org/security/2006/dsa-1017
http://www.debian.org/security/2006/dsa-1018
http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git%3Ba=blob%3Bh=1cf41a8a8db3080c9a9243e77c5c447c8e694f87%3Bhb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd%3Bf=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb94c62c252796f42bb83fe40960d12f3ea5a82a
http://www.mandriva.com/security/advisories?name=MDKSA-2006:072
http://www.redhat.com/support/errata/RHSA-2006-0101.html
http://www.redhat.com/support/errata/RHSA-2006-0140.html
http://www.securityfocus.com/bid/16044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11346
https://usn.ubuntu.com/231-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*

History

21 Nov 2024, 00:02

Type Values Removed Values Added
References () http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html - () http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html -
References () http://marc.info/?l=linux-kernel&m=112431016816937&w=2 - () http://marc.info/?l=linux-kernel&m=112431016816937&w=2 -
References () http://marc.info/?l=linux-kernel&m=112439084918917&w=2 - () http://marc.info/?l=linux-kernel&m=112439084918917&w=2 -
References () http://marc.info/?l=linux-kernel&m=112508479212728&w=2 - () http://marc.info/?l=linux-kernel&m=112508479212728&w=2 -
References () http://secunia.com/advisories/18203 - () http://secunia.com/advisories/18203 -
References () http://secunia.com/advisories/18510 - () http://secunia.com/advisories/18510 -
References () http://secunia.com/advisories/18562 - () http://secunia.com/advisories/18562 -
References () http://secunia.com/advisories/19038 - () http://secunia.com/advisories/19038 -
References () http://secunia.com/advisories/19369 - () http://secunia.com/advisories/19369 -
References () http://secunia.com/advisories/19374 - () http://secunia.com/advisories/19374 -
References () http://www.debian.org/security/2006/dsa-1017 - () http://www.debian.org/security/2006/dsa-1017 -
References () http://www.debian.org/security/2006/dsa-1018 - () http://www.debian.org/security/2006/dsa-1018 -
References () http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git%3Ba=blob%3Bh=1cf41a8a8db3080c9a9243e77c5c447c8e694f87%3Bhb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd%3Bf=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch - () http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git%3Ba=blob%3Bh=1cf41a8a8db3080c9a9243e77c5c447c8e694f87%3Bhb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd%3Bf=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch -
References () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb94c62c252796f42bb83fe40960d12f3ea5a82a - () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb94c62c252796f42bb83fe40960d12f3ea5a82a -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:072 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:072 -
References () http://www.redhat.com/support/errata/RHSA-2006-0101.html - () http://www.redhat.com/support/errata/RHSA-2006-0101.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0140.html - () http://www.redhat.com/support/errata/RHSA-2006-0140.html -
References () http://www.securityfocus.com/bid/16044 - () http://www.securityfocus.com/bid/16044 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11346 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11346 -
References () https://usn.ubuntu.com/231-1/ - () https://usn.ubuntu.com/231-1/ -

07 Nov 2023, 01:57

Type Values Removed Values Added
References
  • {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=cb94c62c252796f42bb83fe40960d12f3ea5a82a', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=cb94c62c252796f42bb83fe40960d12f3ea5a82a', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git;a=blob;h=1cf41a8a8db3080c9a9243e77c5c447c8e694f87;hb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd;f=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git;a=blob;h=1cf41a8a8db3080c9a9243e77c5c447c8e694f87;hb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd;f=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://www.kernel.org/git/?p=linux/kernel/git/chrisw/stable-queue.git%3Ba=blob%3Bh=1cf41a8a8db3080c9a9243e77c5c447c8e694f87%3Bhb=9c5fcb99af7c157be45e9d53aeb857ded5211fcd%3Bf=2.6.12.6/fix-dst-leak-in-icmp_push_reply.patch -
  • () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb94c62c252796f42bb83fe40960d12f3ea5a82a -

Information

Published : 2005-11-27 00:03

Updated : 2024-11-21 00:02


NVD link : CVE-2005-3848

Mitre link : CVE-2005-3848

CVE.ORG link : CVE-2005-3848


JSON object : View

Products Affected

linux

  • linux_kernel