7.8 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
0.889 High
EPSS
Percentile
98.7%
A memory freeing vulnerability in the Linux kernel module ip_nat_snmp_basic
can be exploited to create a denial-of-service condition.
**ip_nat_snmp_basic**
The ip_nat_snmp_basic
IP NAT module is intended for use with SNMP network discovery and monitoring applications where target networks use conflicting private IP addresses .
**snmp_trap_decode()**
The snmp_trap_decode(``)
function decodes v1 and v2 SNMP messages.
The Problem
The function snmp_trap_decode()
in the Linux kernel module ip_nat_snmp_basic
fails to properly free memory when handling certain SNMP packets.
A remote attacker could cause a system running Linux kernel version < 2.6.16.18 with the ip_nat_snmp_basic
module loaded to crash. This results in a denial-of-service condition.
Apply an update
See the systems affected section of this document for information about specific vendors. Users who compile the Linux kernel from source are encouraged to upgrade to Linux kernel version 2.6.16.18.
Do not use**ip_nat_snmp_basic**
Do not load the ip_nat_snmp_basic
kernel module if it is not needed.
Restrict Access
Limit access to SNMP ports (default 161/udp
and 162/udp
) to trusted hosts.
681569
Filter by status: All Affected Not Affected Unknown
Filter by content: __ Additional information available
__ Sort by: Status Alphabetical
Expand all
Javascript is disabled. Click here to view vendors.
Updated: June 09, 2006
Affected
We have not received a statement from the vendor.
The vendor has not provided us with any further information regarding this vulnerability.
Mandriva, Inc. has published Mandriva Linux Security Advisory MDKSA-2006:087 in response to this issue. Users are encouraged to review this advisory and apply the patches it refers to.
If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23681569 Feedback>).
Updated: June 09, 2006
Affected
We have not received a statement from the vendor.
The vendor has not provided us with any further information regarding this vulnerability.
Trustix has published Trustix Secure Linux Security Advisory #2006-0030 in response to this issue. Users are encouraged to review this advisory and apply the patches it refers to.
If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23681569 Feedback>).
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
This vulnerability was reported by Patrick McHardy.
This document was written by Ryan Giobbi.
CVE IDs: | CVE-2006-2444 |
---|---|
Severity Metric: | 2.69 Date Public: |