PT-2004-1102 · Gentoo+1 · Aa-Sources+1

Published

2004-05-02

·

Updated

2017-07-11

·

CVE-2004-1983

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions aa-sources versions prior to 2.4.23-r2 Linux kernel 2.6 (with PaX patches and Address Space Layout Randomization (ASLR) enabled)
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The arch get unmapped area function in mmap.c in the PaX patches for the Linux kernel allows local users to cause a denial of service (infinite loop) via unknown attack vectors.
Recommendations For aa-sources versions prior to 2.4.23-r2, update to version 2.4.23-r2 or later. For Linux kernel 2.6 with PaX patches and ASLR enabled, consider disabling ASLR as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09455
CVE-2004-1983

Affected Products

Linux Kernel
Aa-Sources