When running the command: ping -s 65468 -R some_ip_address ( -R records route) the system starts to print on the screen kernel dumps, freezes completely and after few seconds the system will reboot. Local Linux users can use this as an effective Denial of Service attack.
Credit:
The information has been provided by: Eduardo Cruz.
Vulnerable systems:
Linux 2.0.35
Linux 2.0.36
Linux 2.0.38
Immune systems:
Linux 2.2.0 and above
Workaround:
For those using RedHat 5.2 an SRPM and i368 RPM containing an alternative ping program can be downloaded via FTP at: ftp://ox.compsoc.net/users/swhite/ping/
Patch
The following patch can be used to patch Linux 2.0.38: