PT-2004-1102 · Gentoo+1 · Aa-Sources+1
Publicado
2004-05-02
·
Atualizado
2017-07-11
·
CVE-2004-1983
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
aa-sources versions prior to 2.4.23-r2
Linux kernel 2.6 (with PaX patches and Address Space Layout Randomization (ASLR) enabled)
Description
The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The
arch get unmapped area function in mmap.c in the PaX patches for the Linux kernel allows local users to cause a denial of service (infinite loop) via unknown attack vectors.Recommendations
For aa-sources versions prior to 2.4.23-r2, update to version 2.4.23-r2 or later.
For Linux kernel 2.6 with PaX patches and ASLR enabled, consider disabling ASLR as a temporary workaround until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Aa-Sources