The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | * | 2.6.21 (including) |
Linux | Ubuntu | upstream | * |
Linux-source-2.6.20 | Ubuntu | feisty | * |
Linux-source-2.6.22 | Ubuntu | gutsy | * |