Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2007-2480

Published: 3 May 2007

The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.

Notes

AuthorNote
kees
Cannot reproduce.  Is this really an issue for kernels prior to 2.6.21?

Priority

Low

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
hardy Not vulnerable
(2.6.22-12.39)
upstream
Released (2.6.22)
linux-source-2.6.15
Launchpad, Ubuntu, Debian
dapper Not vulnerable

upstream Needs triage

linux-source-2.6.17
Launchpad, Ubuntu, Debian
edgy Not vulnerable

upstream Needs triage

linux-source-2.6.20
Launchpad, Ubuntu, Debian
feisty Ignored
(end of life)
upstream Needs triage

linux-source-2.6.22
Launchpad, Ubuntu, Debian
gutsy
Released (2.6.22-12.39)
upstream Needs triage