Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel 缓冲区错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 2.4.36.6之前的2.4.x版本和2.6.25.5之前的2.6.x版本存在缓冲区错误漏洞,该漏洞源于解码器没有正确地计算缓冲区大小,远程攻击者向有漏洞的系统发送了特制的BER编码数据可以触发缓冲区溢出,导致拒绝服务或执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A