Debian Security Advisory

DSA-492-1 iproute -- denial of service

Date Reported:
18 Apr 2004
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 242994.
In the Bugtraq database (at SecurityFocus): BugTraq ID 9092.
In Mitre's CVE dictionary: CVE-2003-0856.
More information:

Herbert Xu reported that local users could cause a denial of service against iproute, a set of tools for controlling networking in Linux kernels. iproute uses the netlink interface to communicate with the kernel, but failed to verify that the messages it received came from the kernel (rather than from other user processes).

For the current stable distribution (woody) this problem has been fixed in version 20010824-8woody1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you update your iproute package.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Intel IA-32:
Intel IA-64:
Motorola 680x0:
Big endian MIPS:
Little endian MIPS:
IBM S/390:
Sun Sparc:

MD5 checksums of the listed files are available in the original advisory.