The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.
References
Information
Published : 2011-01-03 12:00
Updated : 2023-02-12 20:27
NVD link : CVE-2010-3873
Mitre link : CVE-2010-3873
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
debian
- debian_linux
suse
- linux_enterprise_server
opensuse
- opensuse
linux
- linux_kernel