The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.
http://www.ubuntu.com/usn/usn-416-1
http://www.trustix.org/errata/2007/0002/
http://www.securityfocus.com/bid/21883
http://www.securityfocus.com/bid/21835
http://www.securityfocus.com/archive/1/471457
http://www.novell.com/linux/security/advisories/2007_35_kernel.html
http://www.novell.com/linux/security/advisories/2007_30_kernel.html
http://www.novell.com/linux/security/advisories/2007_21_kernel.html
http://www.novell.com/linux/security/advisories/2007_18_kernel.html
http://www.mandriva.com/security/advisories?name=MDKSA-2007:040
http://www.mandriva.com/security/advisories?name=MDKSA-2007:025
http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
http://secunia.com/advisories/25691
http://secunia.com/advisories/25683
http://secunia.com/advisories/25226
http://secunia.com/advisories/24547
http://secunia.com/advisories/24100
http://secunia.com/advisories/24098
http://secunia.com/advisories/23752
http://secunia.com/advisories/23609