{"vuid":"VU#681569","idnumber":"681569","name":"Linux Kernel may fail to properly handle SNMP packets","keywords":["Linux","Kernel","DoS","SNMP","snmp_trap_decode","ip_nat_snmp_basic"],"overview":"A memory-freeing vulnerability in the Linux kernel module ip_nat_snmp_basic can be exploited to create a denial-of-service condition.","clean_desc":"ip_nat_snmp_basic The ip_nat_snmp_basic IP NAT module is intended for use with SNMP network discovery and monitoring applications where target networks use conflicting private IP addresses . snmp_trap_decode() The snmp_trap_decode()function decodes v1 and v2 SNMP messages. The Problem The function snmp_trap_decode() in the Linux kernel module ip_nat_snmp_basic fails to properly free memory when handling certain SNMP packets.","impact":"A remote attacker could cause a system running Linux kernel version < 2.6.16.18 with the ip_nat_snmp_basic module loaded to crash. This results in a denial-of-service condition.","resolution":"Apply an update\nSee the systems affected section of this document for information about specific vendors. Users who compile the Linux kernel from source are encouraged to upgrade to Linux kernel version 2.6.16.18.","workarounds":"Do not use ip_nat_snmp_basic Do not load the ip_nat_snmp_basic kernel module if it is not needed. Restrict Access Limit access to SNMP ports (default 161/udp and 162/udp) to trusted hosts.","sysaffected":"","thanks":"This vuln\nerability was reported by \nPatrick McHardy","author":"This document was written by Ryan Giobbi.","public":["http://secunia.com/advisories/20225/","http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.18","http://secunia.com/advisories/20182/"],"cveids":["CVE-2006-2444"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2006-05-23T13:47:24Z","publicdate":"2006-05-23T00:00:00Z","datefirstpublished":"2006-06-09T15:36:47Z","dateupdated":"2006-07-13T20:42:07Z","revision":30,"vrda_d1_directreport":"0","vrda_d1_population":"3","vrda_d1_impact":"2","cam_widelyknown":"20","cam_exploitation":"1","cam_internetinfrastructure":"8","cam_population":"10","cam_impact":"3","cam_easeofexploitation":"11","cam_attackeraccessrequired":"15","cam_scorecurrent":"2.6915625","cam_scorecurrentwidelyknown":"2.6915625","cam_scorecurrentwidelyknownexploited":"4.455","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":2.6915625,"vulnote":null}