The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.
References
Information
Published : 2011-01-03 20:00
Updated : 2020-08-14 15:29
NVD link : CVE-2010-3873
Mitre link : CVE-2010-3873
JSON object : View
Products Affected
linux
- linux_kernel
opensuse
- opensuse
debian
- debian_linux
suse
- linux_enterprise_server
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
