SB2004123103 - Improper input validation in Linux kernel



SB2004123103 - Improper input validation in Linux kernel

Published: December 31, 2004

Security Bulletin ID SB2004123103
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2004-0997)

The vulnerability allows a local user to read and manipulate data.

Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors. This vulnerability is addressed in the following product release: Linux, Linux kernel, 2.4.17


Remediation

Install update from vendor's website.