First published: Mon Jan 23 2006(Updated: )
ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | =2.6.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0036 has a severity rating that indicates it can lead to denial of service, specifically memory corruption or crashes.
To fix CVE-2006-0036, it is recommended to upgrade to the latest version of the Linux kernel that addresses this vulnerability.
Individuals using Linux kernel version 2.6.14 and earlier are affected by CVE-2006-0036.
CVE-2006-0036 allows remote attackers to exploit a vulnerability in the PPTP NAT helper to cause denial of service.
Yes, CVE-2006-0036 can be exploited remotely through specially crafted PPTP_IN_CALL_REQUEST packets.