PT-2004-3734 · Linux+1 · Linux Kernel+1

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2004-1072

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.x up to 2.4.27 Linux kernel versions 2.6.x up to 2.6.8 Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs version Debian GNU/Linux kernel-image-2.4.18-sun4u version Debian GNU/Linux kernel-image-2.4.18-sun4u-smp version Debian GNU/Linux kernel-image-2.4.19-sparc version Debian GNU/Linux kernel-image-2.4.19-sun4u version Debian GNU/Linux kernel-image-2.4.19-sun4u-smp version Debian GNU/Linux kernel-headers-2.4.18-sparc version Debian GNU/Linux kernel-headers-2.4.19-sparc version Debian GNU/Linux kernel-patch-benh version
Description The issue is related to multiple vulnerabilities in the Linux kernel and Debian GNU/Linux kernel packages. These vulnerabilities can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information. The binfmt elf loader in the Linux kernel may create an interpreter name string that is not NULL terminated, potentially causing buffer overflows that allow local users to cause a denial of service and possibly execute arbitrary code.
Recommendations For Linux kernel versions 2.4.x up to 2.4.27, update to a version later than 2.4.27. For Linux kernel versions 2.6.x up to 2.6.8, update to a version later than 2.6.8. For Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs, update to a version that is not vulnerable. For Debian GNU/Linux kernel-image-2.4.18-sun4u, update to a version that is not vulnerable. For Debian GNU/Linux kernel-image-2.4.18-sun4u-smp, update to a version that is not vulnerable. For Debian GNU/Linux kernel-image-2.4.19-sparc, update to a version that is not vulnerable. For Debian GNU/Linux kernel-image-2.4.19-sun4u, update to a version that is not vulnerable. For Debian GNU/Linux kernel-image-2.4.19-sun4u-smp, update to a version that is not vulnerable. For Debian GNU/Linux kernel-headers-2.4.18-sparc, update to a version that is not vulnerable. For Debian GNU/Linux kernel-headers-2.4.19-sparc, update to a version that is not vulnerable. For Debian GNU/Linux kernel-patch-benh, update to a version that is not vulnerable.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03380
BDU:2015-03381
BDU:2015-03382
BDU:2015-03383
BDU:2015-03384
BDU:2015-03385
BDU:2015-03576
BDU:2015-03577
CVE-2004-1072
DSA-1067-1
DSA-1069-1
DSA-1070-1
DSA-1082-1
RHSA-2004:549

Affected Products

Debian
Linux Kernel