Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-2323-1 Critical: Radvd Buffer Overflow And DoS Threats

debian
Calendar Grey October 28, 2011
Debian Logo
Enhance your system's security by updating the radvd packages due to significant vulnerabilities outlined in the Ubuntu Security Notice USN-1234-2.
Multiple security issues were discovered by Vasiliy Kulikov in radvd, an IPv6 Router Advertisement daemon: CVE-2011-3602

Summary

Multiple security issues were discovered by Vasiliy Kulikov in radvd, an
IPv6 Router Advertisement daemon:

CVE-2011-3602

set_interface_var() function doesn't check the interface name, which is
chosen by an unprivileged user. This could lead to an arbitrary file
overwrite if the attacker has local access, or specific files overwrites
otherwise.

CVE-2011-3604

process_ra() function lacks multiple buffer length checks which could
lead to memory reads outside the stack, causing a crash of the daemon.

CVE-2011-3605

process_rs() function calls mdelay() (a function to wait for a defined
time) unconditionnally when running in unicast-only mode. As this call
is in the main thread, that means all request processing is delayed (for
a time up to MAX_RA_DELAY_TIME, 500 ms by default). An attacked could
flood the daemon with router solicitations in order to fill the input
queue, causing a temporary denial of service (processing would be
stopped during all the mdelay() calls).
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: radvd
CVE ID: CVE-2011-3602 CVE-2011-3604 CVE-2011-3605

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here