>> Linux Kernel "ip_route_input" Function Local Denial of Service Vulnerability
Title : Linux Kernel "ip_route_input" Function Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-1399 CVE ID : CVE-2006-1525
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-04-18
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This flaw is due to a NULL pointer dereference in "ip_route_input" and "inet_rtm_getroute" [net/ipv4/route.c] when handling a specially crafted "route" command for a multicast IP address, which could be exploited by malicious users to crash a vulnerable system, creating a denial of service condition.