Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70987
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1257-1 (radvd)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to radvd
announced via advisory USN-1257-1.

Details:

Vasiliy Kulikov discovered that radvd incorrectly parsed the
ND_OPT_DNSSL_INFORMATION option. A remote attacker could exploit this with
a specially-crafted request and cause the radvd daemon to crash, or
possibly execute arbitrary code. The default compiler options for affected
releases should reduce the vulnerability to a denial of service. This issue
only affected Ubuntu 11.04 and 11.10. (CVE-2011-3601)

Vasiliy Kulikov discovered that radvd incorrectly filtered interface names
when creating certain files. A local attacker could exploit this to
overwrite certain files on the system, bypassing intended permissions.
(CVE-2011-3602)

Vasiliy Kulikov discovered that radvd incorrectly handled certain lengths.
A remote attacker could exploit this to cause the radvd daemon to crash,
resulting in a denial of service. (CVE-2011-3604)

Vasiliy Kulikov discovered that radvd incorrectly handled delays when used
in unicast mode, which is not the default in Ubuntu. If used in unicast
mode, a remote attacker could cause radvd outages, resulting in a denial of
service. (CVE-2011-3605)

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
radvd 1:1.8-1ubuntu0.1

Ubuntu 11.04:
radvd 1:1.7-1ubuntu0.1

Ubuntu 10.10:
radvd 1:1.6-1ubuntu0.1

Ubuntu 10.04 LTS:
radvd 1:1.3-1.1ubuntu0.1

http://www.securityspace.com/smysecure/catid.html?in=USN-1257-1

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3601
USN-1257-1
http://www.ubuntu.com/usn/USN-1257-1
[oss-security] 20111007 radvd 1.8.2 released with security fixes
http://www.openwall.com/lists/oss-security/2011/10/06/3
http://www.litech.org/radvd/CHANGES
Common Vulnerability Exposure (CVE) ID: CVE-2011-3602
DSA-2323
http://www.debian.org/security/2011/dsa-2323
https://github.com/reubenhwk/radvd/commit/92e22ca23e52066da2258df8c76a2dca8a428bcc
Common Vulnerability Exposure (CVE) ID: CVE-2011-3604
Common Vulnerability Exposure (CVE) ID: CVE-2011-3605
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.