PT-2004-1562 · Linux · Linux Kernel

Published

2004-04-30

·

Updated

2018-05-03

·

CVE-2004-0424

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.22 through 2.4.25 Linux kernel versions 2.6.1 through 2.6.3
Description The issue is related to an integer overflow in the ip setsockopt function. This overflow can be triggered by local users via the MCAST MSFILTER socket option, potentially leading to a denial of service (crash) or the execution of arbitrary code.
Recommendations For Linux kernel versions 2.4.22 through 2.4.25, consider upgrading to a version outside of this range to mitigate the risk. For Linux kernel versions 2.6.1 through 2.6.3, consider upgrading to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the ip setsockopt function or the MCAST MSFILTER socket option to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0424
RHSA-2004:183

Affected Products

Linux Kernel