PT-2003-2512 · Red Hat+3 · Red Hat+4

Zen-Parse

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2004-0109

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-pcmcia-modules versions 2.4.18-1-686 through 2.4.18-1-686 Debian GNU/Linux kernel-doc versions 2.4.16 through 2.4.20 Debian GNU/Linux kernel-image versions 2.4.16 through 2.4.20 Debian GNU/Linux kernel-headers versions 2.4.16 through 2.4.20 Debian GNU/Linux kernel-source versions 2.4.16 through 2.4.20 Debian GNU/Linux kernel-patch versions 2.4.16 through 2.4.20 Red Hat Linux kernel versions 2.4.20 and earlier Red Hat Linux kernel-bigmem versions 2.4.20 and earlier Red Hat Linux kernel-BOOT versions 2.4.20 and earlier Red Hat Linux kernel-doc versions 2.4.20 and earlier Red Hat Linux kernel-smp versions 2.4.20 and earlier Gentoo Linux aa-sources versions prior to 2.4.23-r2
Description The issue affects multiple components of the Linux kernel in various operating systems, including Debian GNU/Linux and Red Hat Linux. Exploitation of these vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited locally or remotely, depending on the specific component and version. A buffer overflow in the ISO9660 file system component allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.
Recommendations For Debian GNU/Linux kernel-pcmcia-modules versions 2.4.18-1-686 and earlier, update to a newer version. For Debian GNU/Linux kernel-doc versions 2.4.16 through 2.4.20, update to a newer version. For Debian GNU/Linux kernel-image versions 2.4.16 through 2.4.20, update to a newer version. For Debian GNU/Linux kernel-headers versions 2.4.16 through 2.4.20, update to a newer version. For Debian GNU/Linux kernel-source versions 2.4.16 through 2.4.20, update to a newer version. For Debian GNU/Linux kernel-patch versions 2.4.16 through 2.4.20, update to a newer version. For Red Hat Linux kernel versions 2.4.20 and earlier, update to a newer version. For Red Hat Linux kernel-bigmem versions 2.4.20 and earlier, update to a newer version. For Red Hat Linux kernel-BOOT versions 2.4.20 and earlier, update to a newer version. For Red Hat Linux kernel-doc versions 2.4.20 and earlier, update to a newer version. For Red Hat Linux kernel-smp versions 2.4.20 and earlier, update to a newer version. For Gentoo Linux aa-sources versions prior to 2.4.23-r2, update to version 2.4.23-r2 or later. As a temporary workaround, consider disabling the vulnerable components until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the affected kernel versions until an update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01287
BDU:2015-01288
BDU:2015-01289
BDU:2015-01290
BDU:2015-01291
BDU:2015-01292
BDU:2015-01368
BDU:2015-01369
BDU:2015-01370
BDU:2015-01371
BDU:2015-01372
BDU:2015-01373
BDU:2015-01374
BDU:2015-01375
BDU:2015-01379
BDU:2015-01380
BDU:2015-01381
BDU:2015-01382
BDU:2015-01383
BDU:2015-01384
BDU:2015-01385
BDU:2015-01386
BDU:2015-01387
BDU:2015-01388
BDU:2015-01389
BDU:2015-01390
BDU:2015-01391
BDU:2015-01392
BDU:2015-01393
BDU:2015-01394
BDU:2015-01395
BDU:2015-01396
BDU:2015-01397
BDU:2015-01398
BDU:2015-01399
BDU:2015-01400
BDU:2015-01401
BDU:2015-01402
BDU:2015-01775
BDU:2015-01776
BDU:2015-01777
BDU:2015-01778
BDU:2015-01779
BDU:2015-01780
BDU:2015-01781
BDU:2015-02092
BDU:2015-02093
BDU:2015-02094
BDU:2015-02095
BDU:2015-02096
BDU:2015-02097
BDU:2015-02098
BDU:2015-02099
BDU:2015-02100
BDU:2015-02101
BDU:2015-02102
BDU:2015-02103
BDU:2015-02104
BDU:2015-02105
BDU:2015-02106
BDU:2015-02107
BDU:2015-02108
BDU:2015-02109
BDU:2015-02110
BDU:2015-02111
BDU:2015-02112
BDU:2015-02113
BDU:2015-02114
BDU:2015-02115
BDU:2015-02116
BDU:2015-02117
BDU:2015-02118
BDU:2015-02119
BDU:2015-02120
BDU:2015-02121
BDU:2015-02122
BDU:2015-02123
BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
BDU:2015-09455
CVE-2004-0109
DSA-479
DSA-480
DSA-481
DSA-482
DSA-489
DSA-491
DSA-495
RHSA-2004:183

Affected Products

Debian
Gentoo Linux
Linux Kernel
Red Hat
Aa-Sources