CVE-2006-4093
published 2006-08-21CVE-2006-4093: Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the…
PriorityP411medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.47%
38.4th percentile
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | >= 2.4.0 < 2.4.33.1 | 2.4.33.1 |
| linux | linux_kernel | >= 2.6.0 < 2.6.17.9 | 2.6.17.9 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_ubuntu5.0MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm27-gqxx-cpcx: Linux kernel 2
ghsa_unreviewed·2022-05-01
CVE-2006-4093 [MEDIUM] GHSA-xm27-gqxx-cpcx: Linux kernel 2
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2006-09-15·CVSS 5.0
CVE-2006-2934 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
A Denial of service vulnerability was reported in iptables' SCTP
conntrack module. On computers which use this iptables module, a
remote attacker could expoit this to trigger a kernel crash.
(CVE-2006-2934)
A buffer overflow has been discovered in the dvd_read_bca() function.
By inserting a specially crafted DVD, USB stick, or similar
automatically mounted removable device, a local user could crash the
machine or potentially even execute arbitrary code with full root
privileges. (CVE-2006-2935)
The ftdi_sio driver for serial USB ports did not limit the amount of
pending data to be written. A local user could exploit this to drain
all available kernel memory and thus render the system unusable.
(CVE-2006-2936)
Ja
Red Hat
security flaw
vendor_redhat·2006-08-17·CVSS 4.9
CVE-2006-4093 [MEDIUM] security flaw
security flaw
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4093 security flaw
bugzilla·2018-08-16·CVSS 4.9
CVE-2006-4093 [MEDIUM] CVE-2006-4093 security flaw
CVE-2006-4093 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
Bugzilla
CVE-2006-4093 Local DoS through uncleared HID0[31]
bugzilla·2006-08-08·CVSS 4.9
CVE-2006-4093 [MEDIUM] CVE-2006-4093 Local DoS through uncleared HID0[31]
CVE-2006-4093 Local DoS through uncleared HID0[31]
Report from Olof Johansson:
On PPC970, having HID0[31] (en_attn) set makes it possible to wedge the machine
by just doing an 'asm volatile("attn");' from userspace, clearly a local DoS
exposure. Apple firmware seems to set it and we don't clear it at boot time.
I'm not aware of any intentional exploits of this. I happened to come across it
by running crash01 from LTP, it tries to execute random data as code and kept
locking up my machine.
Discussion:
Created attachment 133779
Proposed patch from Olof Johansson
---
committed in stream E5 build 42.0.3
---
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release. Product Management has requested
further review of this re
http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.9http://secunia.com/advisories/21563http://secunia.com/advisories/21695http://secunia.com/advisories/21847http://secunia.com/advisories/21934http://secunia.com/advisories/22093http://secunia.com/advisories/22148http://secunia.com/advisories/22292http://secunia.com/advisories/22945http://support.avaya.com/elmodocs2/security/ASA-2006-249.htmhttp://www.debian.org/security/2006/dsa-1184http://www.debian.org/security/2006/dsa-1237http://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_22_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_57_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0689.htmlhttp://www.securityfocus.com/bid/19615http://www.ubuntu.com/usn/usn-346-1http://www.vupen.com/english/advisories/2006/3330http://www.vupen.com/english/advisories/2006/3331https://issues.rpath.com/browse/RPL-611https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10666http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.9http://secunia.com/advisories/21563http://secunia.com/advisories/21695http://secunia.com/advisories/21847http://secunia.com/advisories/21934http://secunia.com/advisories/22093http://secunia.com/advisories/22148http://secunia.com/advisories/22292http://secunia.com/advisories/22945http://support.avaya.com/elmodocs2/security/ASA-2006-249.htmhttp://www.debian.org/security/2006/dsa-1184http://www.debian.org/security/2006/dsa-1237http://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_22_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_57_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0689.htmlhttp://www.securityfocus.com/bid/19615http://www.ubuntu.com/usn/usn-346-1http://www.vupen.com/english/advisories/2006/3330http://www.vupen.com/english/advisories/2006/3331https://issues.rpath.com/browse/RPL-611https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10666
2006-08-21
Published