PT-2004-3740 · Linux+1 · Linux Kernel+1

Published

1970-01-01

·

Updated

2024-02-14

·

CVE-2004-1335

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs version Debian GNU/Linux kernel-image-2.4.18-sun4u version Debian GNU/Linux kernel-image-2.4.18-sun4u-smp version Debian GNU/Linux kernel-image-2.4.19-sparc version Debian GNU/Linux kernel-image-2.4.19-sun4u version Debian GNU/Linux kernel-image-2.4.19-sun4u-smp version Linux kernel versions prior to 2.6.10
Description The issue involves multiple vulnerabilities in the Linux kernel of Debian GNU/Linux, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. A memory leak in the ip options get function allows local users to cause a denial of service by repeatedly calling the ip cmsg send function.
Recommendations For Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs version, update to a version that includes the security patches. For Debian GNU/Linux kernel-image-2.4.18-sun4u version, update to a version that includes the security patches. For Debian GNU/Linux kernel-image-2.4.18-sun4u-smp version, update to a version that includes the security patches. For Debian GNU/Linux kernel-image-2.4.19-sparc version, update to a version that includes the security patches. For Debian GNU/Linux kernel-image-2.4.19-sun4u version, update to a version that includes the security patches. For Debian GNU/Linux kernel-image-2.4.19-sun4u-smp version, update to a version that includes the security patches. For Linux kernel versions prior to 2.6.10, update to version 2.6.10 or later to fix the memory leak issue in the ip options get function.

Exploit

Fix

Related Identifiers

BDU:2015-03380
BDU:2015-03381
BDU:2015-03382
BDU:2015-03383
BDU:2015-03384
BDU:2015-03385
BDU:2015-03576
BDU:2015-03577
CVE-2004-1335
DSA-1067-1
DSA-1069-1
DSA-1070-1
DSA-1082-1
RHSA-2004:689

Affected Products

Debian
Linux Kernel