>> Linux Kernel IPv6 Flow Label "ip6fl_get_n()" Local Denial of Service Vulnerability
Title : Linux Kernel IPv6 Flow Label "ip6fl_get_n()" Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4297 CVE ID : CVE-2006-5619
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-11-01
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service. This flaw is due to an infinite loop error in the "ip6fl_get_n()" [net/ipv6/ip6_flowlabel.c] function when handling seqfiles for "/proc/net/ip6_flowlabel", which could be exploited by malicious users to crash an affected system, creating a denial of service condition.