Vulnerability Description
The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.4.34 |
References
- http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34
- http://secunia.com/advisories/23529Patch
- http://secunia.com/advisories/23609
- http://secunia.com/advisories/23752
- http://secunia.com/advisories/24098
- http://secunia.com/advisories/24100
- http://secunia.com/advisories/24547
- http://secunia.com/advisories/25226
- http://secunia.com/advisories/25683
- http://secunia.com/advisories/25691
- http://www.kernel.org/git/?p=linux/kernel/git/wtarreau/linux-2.4.git%3Ba=commitd
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:025
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:040
- http://www.novell.com/linux/security/advisories/2007_18_kernel.html
FAQ
What is CVE-2006-5749?
CVE-2006-5749 is a vulnerability with a CVSS score of 1.7 (LOW). The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has...
How severe is CVE-2006-5749?
CVE-2006-5749 has been rated LOW with a CVSS base score of 1.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5749?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.