Missing release of memory after effective lifetime in Linux kernel - CVE-2002-0046
Published: January 31, 2002 / Updated: October 10, 2017
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet.