>> Linux Kernel "isofs_get_blocks()" ISO9660 Local Denial of Service Vulnerability
Title : Linux Kernel "isofs_get_blocks()" ISO9660 Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4359 CVE ID : CVE-2006-5757
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-11-06
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by malicious users to cause a denial of service. This flaw is due to an infinite loop in the "isofs_get_blocks()" function when handling corrupted data structures, which could be exploited by local attackers to crash a vulnerable system via a malicious ISO9660 image, creating a denial of service condition.