SB2002013101 - Missing release of memory after effective lifetime in Linux kernel
Published: January 31, 2002
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing release of memory after effective lifetime (CVE-ID: CVE-2002-0046)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet.
Remediation
Install update from vendor's website.