Bug 613819 (CVE-2010-2529) - CVE-2010-2529 iputils: denial of service vulnerability in ping
Summary: CVE-2010-2529 iputils: denial of service vulnerability in ping
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2010-2529
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 617612 617613
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-07-12 21:22 UTC by Vincent Danen
Modified: 2021-02-24 22:48 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-03-02 19:21:15 UTC
Embargoed:


Attachments (Terms of Use)
proposed patch to fix the issue (520 bytes, patch)
2010-07-12 21:26 UTC, Vincent Danen
no flags Details | Diff

Description Vincent Danen 2010-07-12 21:22:14 UTC
Ovidiu Mara discovered a flaw in ping (part of iputils).  If a user were to ping a malicious system able to send back a crafted echo reply packet, ping would hang and consume 100% CPU, which could have adverse effect on the usability of the local system.

Comment 2 Vincent Danen 2010-07-12 21:26:05 UTC
Created attachment 431280 [details]
proposed patch to fix the issue

Proposed patch to fix the issue provided by Mandriva.

Comment 10 Vincent Danen 2010-07-15 21:58:14 UTC
This issue has been assigned the name CVE-2010-2529.

Comment 12 Vincent Danen 2010-07-23 14:35:35 UTC
This issue is now public:

http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:138

Comment 14 Vincent Danen 2010-07-23 14:42:42 UTC
Created iputils tracking bugs for this issue

Affects: fedora-all [bug 617613]

Comment 15 Vincent Danen 2010-07-23 15:35:41 UTC
Statement:

(none)

Comment 16 Fedora Update System 2010-08-10 21:31:49 UTC
iputils-20071127-12.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.