CVE-2010-3873

Bug #709372 reported by Tim Gardner
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
Tim Gardner
Hardy
Fix Released
Undecided
Tim Gardner
Karmic
Fix Released
Undecided
Tim Gardner
Lucid
Fix Released
Undecided
Unassigned
Maverick
Fix Released
Undecided
Unassigned
Natty
Fix Released
Undecided
Unassigned
linux-fsl-imx51 (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Won't Fix
Undecided
Unassigned
Lucid
Fix Released
Undecided
Paolo Pisati
Maverick
Invalid
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned
linux-ti-omap4 (Ubuntu)
Invalid
Undecided
Unassigned
Dapper
Invalid
Undecided
Unassigned
Hardy
Invalid
Undecided
Unassigned
Karmic
Invalid
Undecided
Unassigned
Lucid
Invalid
Undecided
Unassigned
Maverick
Fix Released
Undecided
Unassigned
Natty
Invalid
Undecided
Unassigned

Bug Description

The X.25 implementation in the Linux kernel before 2.6.36.2 does not
properly parse facilities, which allows remote attackers to cause a denial
of service (heap memory corruption and panic) or possibly have unspecified
other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE
data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different
vulnerability than CVE-2010-4164.