PT-2004-3752 · Opensuse+4 · Opensuse+4

Al Viro

+1

·

Published

1970-01-01

·

Updated

2018-10-17

·

CVE-2006-6106

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image-2.4.27-4-itanium versions 2.4.27-4-itanium Debian GNU/Linux kernel-image-2.4.27-4-586tsc versions 2.4.27-4-586tsc Debian GNU/Linux kernel-image-2.4.27-4-s390 versions 2.4.27-4-s390 Debian GNU/Linux kernel-image-2.4.27-4-s390-tape versions 2.4.27-4-s390-tape Debian GNU/Linux kernel-image-2.4.27-4-mckinley versions 2.4.27-4-mckinley Debian GNU/Linux kernel-image-2.4.27-4-mckinley-smp versions 2.4.27-4-mckinley-smp Debian GNU/Linux kernel-image-2.4.27-4-686 versions 2.4.27-4-686 Debian GNU/Linux kernel-image-2.4.27-4-686-smp versions 2.4.27-4-686-smp Debian GNU/Linux kernel-image-2.4.27-4-k7 versions 2.4.27-4-k7 Debian GNU/Linux kernel-image-2.4.27-4-k7-smp versions 2.4.27-4-k7-smp Debian GNU/Linux kernel-image-2.4.27-4-sparc64 versions 2.4.27-4-sparc64 Debian GNU/Linux kernel-image-2.4.27-4-sparc64-smp versions 2.4.27-4-sparc64-smp Debian GNU/Linux kernel-image-2.4.27-4-sparc32 versions 2.4.27-4-sparc32 Debian GNU/Linux kernel-image-2.4.27-4-sparc32-smp versions 2.4.27-4-sparc32-smp Debian GNU/Linux kernel-image-2.4.27-4-386 versions 2.4.27-4-386 Debian GNU/Linux kernel-image-2.4.27-4-k6 versions 2.4.27-4-k6 Debian GNU/Linux kernel-image-2.4.27-4-s390x versions 2.4.27-4-s390x openSUSE usbvision-kmp-default versions not specified openSUSE kernel-default-nongpl versions not specified openSUSE kernel-bigsmp-nongpl versions not specified openSUSE kernel-xen-nongpl versions not specified openSUSE kernel-um-nongpl versions not specified openSUSE kernel-smp-nongpl versions not specified openSUSE k smp versions not specified openSUSE k deflt versions not specified openSUSE k itanium2-smp versions not specified openSUSE k itanium2 versions not specified openSUSE k athlon versions not specified openSUSE k page-64k versions not specified openSUSE k numa versions not specified openSUSE k psmp versions not specified openSUSE km nss versions not specified SUSE Linux Enterprise k smp versions not specified SUSE Linux Enterprise k deflt versions not specified SUSE Linux Enterprise k athlon versions not specified SUSE Linux Enterprise k debug versions not specified Linux kernel versions 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x
Description The issue is related to multiple vulnerabilities in various Linux kernel packages and modules, which can lead to a denial of service (crash) and potentially allow remote attackers to execute arbitrary code. The vulnerabilities can be exploited remotely. The affected packages include kernel-image, kernel-headers, pcmcia-modules, hostap-modules, and others. The vulnerabilities are related to buffer overflows in the cmtp recv interopmsg function in the Bluetooth driver.
Recommendations For each affected version, update to a newer version that contains a fix for this issue. As a temporary workaround, consider disabling the vulnerable functions or modules until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the vulnerable parameters or variables in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03581
BDU:2015-03582
BDU:2015-03583
BDU:2015-03584
BDU:2015-03585
BDU:2015-03586
BDU:2015-03587
BDU:2015-03588
BDU:2015-03589
BDU:2015-03590
BDU:2015-03591
BDU:2015-03592
BDU:2015-03593
BDU:2015-03594
BDU:2015-03595
BDU:2015-03596
BDU:2015-03597
BDU:2015-03598
BDU:2015-03599
BDU:2015-03600
BDU:2015-03601
BDU:2015-03602
BDU:2015-03603
BDU:2015-03604
BDU:2015-03605
BDU:2015-03606
BDU:2015-03607
BDU:2015-03608
BDU:2015-03609
BDU:2015-03610
BDU:2015-03611
BDU:2015-03612
BDU:2015-03613
BDU:2015-03614
BDU:2015-03615
BDU:2015-03616
BDU:2015-03617
BDU:2015-03618
BDU:2015-03619
BDU:2015-03620
BDU:2015-03621
BDU:2015-03622
BDU:2015-03623
BDU:2015-03624
BDU:2015-03625
BDU:2015-03626
BDU:2015-03627
BDU:2015-03628
BDU:2015-03629
BDU:2015-03630
BDU:2015-03631
BDU:2015-03632
BDU:2015-03633
BDU:2015-03634
BDU:2015-03635
BDU:2015-03636
BDU:2015-03637
BDU:2015-03638
BDU:2015-03639
BDU:2015-03640
BDU:2015-03641
BDU:2015-03642
BDU:2015-03643
BDU:2015-03644
BDU:2015-03645
BDU:2015-03646
BDU:2015-03647
BDU:2015-03648
BDU:2015-03649
BDU:2015-03650
BDU:2015-03651
BDU:2015-03652
BDU:2015-03653
BDU:2015-03654
BDU:2015-04220
BDU:2015-04221
BDU:2015-04222
BDU:2015-04223
BDU:2015-04224
BDU:2015-04225
BDU:2015-04883
BDU:2015-04884
BDU:2015-04885
BDU:2015-04886
BDU:2015-04887
BDU:2015-04898
BDU:2015-04899
BDU:2015-04900
BDU:2015-04901
BDU:2015-04902
BDU:2015-04903
BDU:2015-04904
BDU:2015-04905
BDU:2015-04906
BDU:2015-04907
BDU:2015-04908
BDU:2015-04909
BDU:2015-04910
BDU:2015-04911
BDU:2015-04912
BDU:2015-04913
BDU:2015-04914
BDU:2015-04915
BDU:2015-04916
BDU:2015-04917
CVE-2006-6106
DSA-1304
DSA-1503-1
DSA-1503-2
RHSA-2007:0014
RHSA-2007_0014

Affected Products

Debian
Linux Kernel
Red Hat
Suse Linux Enterprise
Opensuse