PT-2004-3756 · Linux · Linux Kernel

Infamous41Md

·

Publicado

1970-01-01

·

Atualizado

2008-09-05

·

CVE-2004-2731

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.4.27 Linux kernel versions 2.4.x up to 2.4.27 Linux kernel versions 2.6.x up to 2.6.7
Description The issue involves multiple vulnerabilities in the Linux kernel, specifically in the Sbus PROM driver, that can be exploited to execute arbitrary code. This can be achieved by specifying a small buffer size to the copyin string function or a negative buffer size to the copyin function. The vulnerabilities can be exploited remotely, potentially leading to a disruption of protected information.
Recommendations For Linux kernel versions 2.4.x up to 2.4.27, update to a version later than 2.4.27 to resolve the issue. For Linux kernel versions 2.6.x up to 2.6.7, update to a version later than 2.6.7 to resolve the issue. As a temporary workaround, consider restricting access to the Sbus PROM driver to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03581
BDU:2015-03582
BDU:2015-03583
BDU:2015-03584
BDU:2015-03585
BDU:2015-03586
BDU:2015-03587
BDU:2015-03588
BDU:2015-03589
BDU:2015-03590
BDU:2015-03591
BDU:2015-03592
BDU:2015-03593
BDU:2015-03594
BDU:2015-03595
BDU:2015-03596
BDU:2015-03597
BDU:2015-03598
BDU:2015-03599
BDU:2015-03600
BDU:2015-03601
BDU:2015-03602
BDU:2015-03603
BDU:2015-03604
BDU:2015-03605
BDU:2015-03606
BDU:2015-03607
BDU:2015-03608
BDU:2015-03609
BDU:2015-03610
BDU:2015-03611
BDU:2015-03612
BDU:2015-03613
BDU:2015-03614
BDU:2015-03615
BDU:2015-03616
BDU:2015-03617
BDU:2015-03618
BDU:2015-03619
BDU:2015-03620
BDU:2015-03621
BDU:2015-03622
BDU:2015-03623
BDU:2015-03624
BDU:2015-03625
BDU:2015-03626
BDU:2015-03627
BDU:2015-03628
BDU:2015-03629
BDU:2015-03630
BDU:2015-03631
BDU:2015-03632
BDU:2015-03633
BDU:2015-03634
BDU:2015-03635
BDU:2015-03636
BDU:2015-03637
BDU:2015-03638
BDU:2015-03639
BDU:2015-03640
BDU:2015-03641
BDU:2015-03642
BDU:2015-03643
BDU:2015-03644
BDU:2015-03645
BDU:2015-03646
BDU:2015-03647
BDU:2015-03648
BDU:2015-03649
BDU:2015-03650
BDU:2015-03651
BDU:2015-03652
BDU:2015-03653
BDU:2015-03654
CVE-2004-2731
DSA-1503-1
DSA-1503-2

Produtos afetados

Linux Kernel