PT-2004-1562 · Linux · Linux Kernel
Published
2004-04-30
·
Updated
2018-05-03
·
CVE-2004-0424
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4.22 through 2.4.25
Linux kernel versions 2.6.1 through 2.6.3
Description
The issue is related to an integer overflow in the
ip setsockopt function. This overflow can be triggered by local users via the MCAST MSFILTER socket option, potentially leading to a denial of service (crash) or the execution of arbitrary code.Recommendations
For Linux kernel versions 2.4.22 through 2.4.25, consider upgrading to a version outside of this range to mitigate the risk.
For Linux kernel versions 2.6.1 through 2.6.3, consider upgrading to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the
ip setsockopt function or the MCAST MSFILTER socket option to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel