>> Linux Kernel "ext2_lookup()" Data Stream Handling Denial of Service Vulnerability
Title : Linux Kernel "ext2_lookup()" Data Stream Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4487 CVE ID : CVE-2006-6054
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-11-14
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by malicious users to cause a denial of service. This flaw is due to errors in the "ext2_lookup()" and "ext2_check_page()" functions when handling corrupted data streams, which could be exploited by local attackers to crash a vulnerable system via a malicious ext2 image, creating a denial of service condition.