PT-2004-3717 · Linux · Linux Kernel
Publicado
1970-01-01
·
Atualizado
2010-04-02
·
CVE-2004-2607
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4 up to 2.4.29-rc1
Linux kernel versions 2.6.x up to 2.6.5
Description
The issue is related to a numeric casting discrepancy in the sdla xfer function of the Linux kernel, which allows local users to read portions of kernel memory via a large len argument. This can lead to a violation of protected information accessibility. The vulnerability can be exploited remotely.
Recommendations
For Linux kernel versions 2.4 up to 2.4.29-rc1: update to a version later than 2.4.29-rc1 to resolve the issue.
For Linux kernel versions 2.6.x up to 2.6.5: update to a version later than 2.6.5 to resolve the issue.
As a temporary workaround, consider restricting access to the sdla xfer function until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel