PT-2004-3683 · Suse+3 · Suse Linux Enterprise+3
Al Viro
+1
·
Publicado
1970-01-01
·
Atualizado
2018-10-19
·
CVE-2005-2490
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Debian GNU/Linux kernel versions prior to 2.6.13.1
SUSE Linux Enterprise kernel (affected versions not specified)
Description
The issue involves multiple vulnerabilities in the Linux kernel, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to the information provided, the exploitation can occur through a stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1, allowing local users to execute arbitrary code by calling sendmsg and modifying the message contents in another thread.
Recommendations
For Debian GNU/Linux kernel versions prior to 2.6.13.1, update to version 2.6.13.1 or later to resolve the issue.
For SUSE Linux Enterprise kernel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Linux Kernel
Red Hat
Suse Linux Enterprise