Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2004-1334
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1334

Description:
Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18522

MISC
  http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html

FULLDISC
  http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=110383108211524&w=2

BID
  11956


Return to the previous page.