>> Linux Kernel PPP Over X/Ethernet Sockets Local Denial of Service Vulnerability
Title : Linux Kernel PPP Over X/Ethernet Sockets Local Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1703 CVE ID : CVE-2007-2525
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-05-08
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by malicious users to cause a denial of service. This issue is caused by memory leak error in the "pppox_unbind_sock()" [drivers/net/pppox.c] function when releasing a connected PPPoE socket before calling the "PPPIOCGCHAN" ioctl, which could be exploited by local attackers to exhaust all available memory resources, creating a denial of service condition.