net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGINAL_DST, which allows local users to obtain portions of potentially sensitive memory.

Subscriptions

Vendors Products
Linux Kernel Subscribe
Enterprise Linux Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1097-1 New Kernel 2.4.27 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1184-1 New Linux 2.6.8 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1184-2 New Linux 2.6.8 packages fix several vulnerabilities
EUVD EUVD EUVD-2006-1347 net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGINAL_DST, which allows local users to obtain portions of potentially sensitive memory.
Ubuntu USN Ubuntu USN USN-281-1 Linux kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://marc.info/?l=linux-netdev&m=114148078223594&w=2 cve-icon cve-icon
http://secunia.com/advisories/19357 cve-icon cve-icon
http://secunia.com/advisories/19955 cve-icon cve-icon
http://secunia.com/advisories/20671 cve-icon cve-icon
http://secunia.com/advisories/21045 cve-icon cve-icon
http://secunia.com/advisories/21136 cve-icon cve-icon
http://secunia.com/advisories/21465 cve-icon cve-icon
http://secunia.com/advisories/21983 cve-icon cve-icon
http://secunia.com/advisories/22093 cve-icon cve-icon
http://secunia.com/advisories/22417 cve-icon cve-icon
http://secunia.com/advisories/22875 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1097 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1184 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:123 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:150 cve-icon cve-icon
http://www.osvdb.org/29841 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0437.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0575.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0579.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0580.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/435490/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/451404/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/451417/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/451419/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/451426/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/17203 cve-icon cve-icon
http://www.trustix.org/errata/2006/0032/ cve-icon cve-icon
http://www.vmware.com/download/esx/esx-202-200610-patch.html cve-icon cve-icon
http://www.vmware.com/download/esx/esx-213-200610-patch.html cve-icon cve-icon
http://www.vmware.com/download/esx/esx-254-200610-patch.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2071 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4502 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/25425 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-1343 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10875 cve-icon cve-icon
https://usn.ubuntu.com/281-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-1343 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sgi

Published:

Updated: 2024-08-07T17:12:20.681Z

Reserved: 2006-03-21T00:00:00.000Z

Link: CVE-2006-1343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-03-21T18:02:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-1343

cve-icon Redhat

Severity : Low

Publid Date: 2006-03-04T00:00:00Z

Links: CVE-2006-1343 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses