PT-2004-1102 · Gentoo+1 · Aa-Sources+1
Published
2004-05-02
·
Updated
2017-07-11
·
CVE-2004-1983
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
aa-sources versions prior to 2.4.23-r2
Linux kernel 2.6 (with PaX patches and Address Space Layout Randomization (ASLR) enabled)
Description
The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The
arch get unmapped area function in mmap.c in the PaX patches for the Linux kernel allows local users to cause a denial of service (infinite loop) via unknown attack vectors.Recommendations
For aa-sources versions prior to 2.4.23-r2, update to version 2.4.23-r2 or later.
For Linux kernel 2.6 with PaX patches and ASLR enabled, consider disabling ASLR as a temporary workaround until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Aa-Sources