PT-2004-1562 · Linux · Linux Kernel

Publicado

2004-04-30

·

Atualizado

2018-05-03

·

CVE-2004-0424

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.22 through 2.4.25 Linux kernel versions 2.6.1 through 2.6.3
Description The issue is related to an integer overflow in the ip setsockopt function. This overflow can be triggered by local users via the MCAST MSFILTER socket option, potentially leading to a denial of service (crash) or the execution of arbitrary code.
Recommendations For Linux kernel versions 2.4.22 through 2.4.25, consider upgrading to a version outside of this range to mitigate the risk. For Linux kernel versions 2.6.1 through 2.6.3, consider upgrading to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the ip setsockopt function or the MCAST MSFILTER socket option to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0424
RHSA-2004:183

Produtos afetados

Linux Kernel