Re: [Full-Disclosure] Linux Kernel sctp_setsockopt() Integer Overflow

From: Tom Rini (trini_at_kernel.crashing.org)
Date: 05/12/04

  • Next message: morning_wood: "MS04-015 - Windows Help Center - Dvdupgrade"
    Date: Tue, 11 May 2004 15:05:15 -0700
    To: Shaun Colley <shaunige@yahoo.co.uk>
    
    

    On Tue, May 11, 2004 at 07:58:56PM +0100, Shaun Colley wrote:

    > ~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
    >
    > Product: Linux Kernel
    > Versions: <= 2.4.25

    Strictly speaking, 2.4.23-pre5 until 2.4.26.

    > Bug: Integer overflow
    > Impact: Attackers may be able to execute
    > arbitrary code with kernel-level
    > privileges.
    > Risk: High
    > Date: May 11, 2004
    > Author: Shaun Colley
    > Email: shaunige yahoo co uk
    > WWW: http://www.nettwerked.co.uk
    [snip]

    -- 
    Tom Rini
    http://gate.crashing.org/~trini/
    

  • Next message: morning_wood: "MS04-015 - Windows Help Center - Dvdupgrade"

    Relevant Pages


  • Quantcast