CVE-2011-3601
Published: 7 October 2011
Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative value in a label_len value.
Notes
Author | Note |
---|---|
mdeslaur | maverick and older don't support ND_OPT_DNSSL_INFORMATION |
Priority
Status
Package | Release | Status |
---|---|---|
radvd Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Not vulnerable
(1:1.3-1.1)
|
|
maverick |
Not vulnerable
(1:1.6-1)
|
|
natty |
Released
(1:1.7-1ubuntu0.1)
|
|
oneiric |
Released
(1:1.8-1ubuntu0.1)
|
|
upstream |
Released
(1.8.2)
|
|
Patches: upstream: https://github.com/reubenhwk/radvd/commit/9dfaaaf740ce784541e76e68de4ae04dce2c0921 |