Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 2.1 product line. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 151242

Summary: CAN-2005-0384 pppd remote DoS
Product: Red Hat Enterprise Linux 2.1 Reporter: Mark J. Cox <mjc>
Component: kernelAssignee: Jim Paradis <jparadis>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: high Docs Contact:
Priority: medium    
Version: 2.1CC: peterm, riel
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard: impact=important,source=vendorsec,reported=20050215,embargo=20050315
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-04-28 15:05:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mark J. Cox 2005-03-16 11:10:24 UTC
See #151240 for POC and patch

+++ This bug was initially created as a clone of Bug #151240 +++

Ben Martel and Stephen Blackheath discovered a DoS attack that a client of pppd
can make that can hang the server machine.  The bug is in the Linux kernel 2.6
(tested on 2.6.9), but it looks like it also exists in the 2.4 series.

Comment 1 Jim Paradis 2005-04-19 17:46:26 UTC
A fix for this problem has been committed to the RHEL21 source pool for kernel
version 2.4.9-e.62

Comment 2 John Flanagan 2005-04-28 15:05:56 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2005-283.html