PT-2004-1562 · Linux · Linux Kernel
Publicado
2004-04-30
·
Atualizado
2018-05-03
·
CVE-2004-0424
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4.22 through 2.4.25
Linux kernel versions 2.6.1 through 2.6.3
Description
The issue is related to an integer overflow in the
ip setsockopt function. This overflow can be triggered by local users via the MCAST MSFILTER socket option, potentially leading to a denial of service (crash) or the execution of arbitrary code.Recommendations
For Linux kernel versions 2.4.22 through 2.4.25, consider upgrading to a version outside of this range to mitigate the risk.
For Linux kernel versions 2.6.1 through 2.6.3, consider upgrading to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the
ip setsockopt function or the MCAST MSFILTER socket option to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel