Linux Kernel多个本地漏洞

漏洞信息详情

Linux Kernel多个本地漏洞

漏洞简介

Linux kernel 2.6.10以前的版本的ip_options_get函数存在整数溢出漏洞。本地用户借助一个包含-1的cmsg_len导致服务拒绝(内核崩溃),引发缓冲区溢出。

漏洞公告

Reportedly, these vulnerabilities are addressed in versions 2.6.10rc3bk5 and 2.4rc of the Linux kernel, but this is not confirmed.
Please see the referenced advisories for more information.
RedHat Fedora Core1

Linux kernel 2.4.17

参考网址

来源: XF
名称: linux-ipoptionsget-dos(18522)
链接:http://xforce.iss.net/xforce/xfdb/18522

来源: FULLDISC
名称: 20041215 fun with linux kernel
链接:http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html

来源: BID
名称: 11956
链接:http://www.securityfocus.com/bid/11956

来源: www.guninski.com
链接:http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html

来源: BUGTRAQ
名称: 20041215 [USN-47-1] Linux kernel vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110383108211524&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享