SB2005030101 - Resource management errors in Linux kernel
Published: March 1, 2005
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource management errors (CVE-ID: CVE-2004-0986)
CWE-ID: CWE-399 - Resource Management Errors
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
Remediation
Install update from vendor's website.
References
- http://rpmfind.net/linux/RPM/suse/updates/9.2/i386/rpm/i586/iptables-1.2.11-4.2.i586.html
- http://www.ciac.org/ciac/bulletins/p-026.shtml
- http://www.debian.org/security/2004/dsa-580
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:125
- http://www.securityfocus.com/bid/11570
- https://bugzilla.fedora.us/show_bug.cgi?id=2252
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17928
- https://www.ubuntu.com/usn/usn-81-1/