7.2
CVSSv2

CVE-2004-0424

Published: 07/07/2004 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 up to and including 2.4.25 and 2.6.1 up to and including 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi propack 3.0

linux linux kernel 2.4.23_ow2

linux linux kernel 2.4.24

linux linux kernel 2.6.3

slackware slackware linux 9.1

linux linux kernel 2.4.22

linux linux kernel 2.6.1

linux linux kernel 2.4.23

linux linux kernel 2.6.2

linux linux kernel 2.4.24_ow1

linux linux kernel 2.4.25

slackware slackware linux current

Exploits

/* setsockopt proof of concept code by Julien TINNES (julien at cr0org) vulnerability found (as always by Paul Starzetz This is only a lame POC which will crash the machine, no root shell here Maybe later, when everybody will have an updated box It should work on 261, 262 and 263 kernels Greets to Christophe Devine, too bad you wasn't ...