UBUNTU-CVE-2015-4004
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-4004
UBUNTU-CVE-2015-4004
Summary:
Details: The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
References: https://ubuntu.com/security/CVE-2015-4004, http://www.openwall.com/lists/oss-security/2015/06/05/7, https://lkml.org/lkml/2015/5/13/739, https://ubuntu.com/security/notices/USN-2989-1, https://ubuntu.com/security/notices/USN-2998-1, https://ubuntu.com/security/notices/USN-3000-1, https://ubuntu.com/security/notices/USN-3001-1, https://ubuntu.com/security/notices/USN-3002-1, https://ubuntu.com/security/notices/USN-3003-1, https://ubuntu.com/security/notices/USN-3004-1, https://www.cve.org/CVERecord?id=CVE-2015-4004
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
