PT-2004-3746 · Linux+2 · Linux Kernel+2
Published
1970-01-01
·
Updated
2017-10-11
·
CVE-2005-0504
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.2.x through 2.6.x before 2.6.22
Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs version
Debian GNU/Linux kernel-image-2.4.18-sun4u version
Debian GNU/Linux kernel-image-2.4.18-sun4u-smp version
Debian GNU/Linux kernel-image-2.4.19-sparc version
Debian GNU/Linux kernel-image-2.4.19-sun4u version
Debian GNU/Linux kernel-image-2.4.19-sun4u-smp version
Debian GNU/Linux kernel-headers-2.4.18-sparc version
Debian GNU/Linux kernel-headers-2.4.19-sparc version
Debian GNU/Linux kernel-patch-benh version
Description
The issue involves multiple vulnerabilities in the Linux kernel and Debian GNU/Linux kernel packages, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow vulnerability in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
Recommendations
For Linux kernel versions 2.2.x through 2.6.x before 2.6.22, update to version 2.6.22 or later to resolve the issue.
For Debian GNU/Linux kernel-image-2.4.18-powerpc-xfs version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-image-2.4.18-sun4u version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-image-2.4.18-sun4u-smp version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-image-2.4.19-sparc version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-image-2.4.19-sun4u version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-image-2.4.19-sun4u-smp version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-headers-2.4.18-sparc version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-headers-2.4.19-sparc version, update to a non-vulnerable version.
For Debian GNU/Linux kernel-patch-benh version, update to a non-vulnerable version.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linux Kernel
Red Hat