Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1304-1 New Linux kernel 2.6.8 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1503-1 New Linux kernel 2.4.27 packages fix several issues
Debian DSA Debian DSA DSA-1503-2 New Linux kernel 2.4.27 packages fix several issues
EUVD EUVD EUVD-2006-6089 Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field.
Ubuntu USN Ubuntu USN USN-416-1 Linux kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.5 cve-icon cve-icon
http://marc.info/?l=linux-kernel&m=116614741607528&w=2 cve-icon cve-icon
http://marc.info/?l=linux-kernel&m=116648929829440&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2007-0014.html cve-icon cve-icon
http://secunia.com/advisories/23408 cve-icon cve-icon
http://secunia.com/advisories/23427 cve-icon cve-icon
http://secunia.com/advisories/23593 cve-icon cve-icon
http://secunia.com/advisories/23609 cve-icon cve-icon
http://secunia.com/advisories/23752 cve-icon cve-icon
http://secunia.com/advisories/23997 cve-icon cve-icon
http://secunia.com/advisories/24098 cve-icon cve-icon
http://secunia.com/advisories/24105 cve-icon cve-icon
http://secunia.com/advisories/24206 cve-icon cve-icon
http://secunia.com/advisories/24547 cve-icon cve-icon
http://secunia.com/advisories/25226 cve-icon cve-icon
http://secunia.com/advisories/25683 cve-icon cve-icon
http://secunia.com/advisories/25691 cve-icon cve-icon
http://secunia.com/advisories/25714 cve-icon cve-icon
http://secunia.com/advisories/27227 cve-icon cve-icon
http://secunia.com/advisories/29058 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1304 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1503 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:002 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:012 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:025 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_18_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_21_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_30_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_35_kernel.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_53_kernel.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/459615/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/471457 cve-icon cve-icon
http://www.securityfocus.com/bid/21604 cve-icon cve-icon
http://www.trustix.org/errata/2007/0002/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-416-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/5037 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218602 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/30912 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-848 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-6106 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10891 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-6106 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T20:12:31.672Z

Reserved: 2006-11-24T05:00:00.000Z

Link: CVE-2006-6106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-12-19T19:28:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2006-6106

cve-icon Redhat

Severity : Moderate

Publid Date: 2006-12-14T00:00:00Z

Links: CVE-2006-6106 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses