>> Linux Kernel 2.6.x "xfrm_sk_policy_insert" Array Index Overflow
Title : Linux Kernel 2.6.x "xfrm_sk_policy_insert" Array Index Overflow VUPEN ID : VUPEN/ADV-2005-1329 CVE ID : CVE-2005-2456 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-08-06
Technical Description
A vulnerability was identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This flaw is due to an error in the "xfrm_sk_policy_insert" [xfrm_user.c] function when processing a "p->dir" value larger than "XFRM_POLICY_OUT", which could be exploited to cause an array index overflow.