Full Disclosure mailing list archives

Re: Linux Kernel sctp_setsockopt() Integer Overflow


From: Tom Rini <trini () kernel crashing org>
Date: Tue, 11 May 2004 15:05:15 -0700

On Tue, May 11, 2004 at 07:58:56PM +0100, Shaun Colley wrote:

~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*

Product:      Linux Kernel
Versions:     <= 2.4.25

Strictly speaking, 2.4.23-pre5 until 2.4.26.

Bug:          Integer overflow
Impact:       Attackers may be able to execute
              arbitrary code with kernel-level
              privileges.
Risk:         High
Date:         May 11, 2004
Author:       Shaun Colley
              Email: shaunige yahoo co uk
              WWW: http://www.nettwerked.co.uk
[snip]

-- 
Tom Rini
http://gate.crashing.org/~trini/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: