Vulnerability Name:

CVE-2004-0424 (CCN-15907)

Assigned:2004-04-20
Published:2004-04-20
Updated:2018-05-03
Summary:Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: SGI
Type: UNKNOWN
20040504-01-U

Source: CCN
Type: Full-Disclosure Mailing List, Tue Apr 20 2004 - 06:30:14 CDT
Linux kernel setsockopt MCAST_MSFILTER integer overflow

Source: MITRE
Type: CNA
CVE-2004-0424

Source: CONECTIVA
Type: UNKNOWN
CLA-2004:852

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2004:852
Fixes for kernel vulnerabilities

Source: BUGTRAQ
Type: UNKNOWN
20040420 Linux kernel setsockopt MCAST_MSFILTER integer overflow

Source: CCN
Type: RHSA-2004-183
kernel security update

Source: MISC
Type: Patch, Vendor Advisory
http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt

Source: CCN
Type: Linux kernel Web site
The Linux Kernel Archives

Source: ENGARDE
Type: Patch, Vendor Advisory
ESA-20040428-004

Source: CCN
Type: Trustix Secure Linux Security Advisory #2004-0022
kernel

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2004:037

Source: SUSE
Type: UNKNOWN
SuSE-SA:2004:010

Source: REDHAT
Type: UNKNOWN
RHSA-2004:183

Source: CCN
Type: SecuriTeam Mailing List, Security Holes & Exploits 22 Apr 2004
Linux kernel 2.x setsockopt MCAST_MSFILTER Exploit

Source: BID
Type: Exploit, Patch, Vendor Advisory
10179

Source: CCN
Type: BID-10179
Linux Kernel Setsockopt MCAST_MSFILTER Integer Overflow Vulnerability

Source: SLACKWARE
Type: UNKNOWN
SSA:2004-119

Source: CCN
Type: slackware-security Mailing List, Wed, 28 Apr 2004 13:56:48 -0700 (PDT)
kernel security updates (SSA:2004-119-01)

Source: XF
Type: UNKNOWN
linux-ipsetsockopt-integer-bo(15907)

Source: XF
Type: UNKNOWN
linux-ipsetsockopt-integer-bo(15907)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:11214

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:939

Source: SUSE
Type: SUSE-SA:2004:010
Linux Kernel: privilege escalation local DoS

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sgi:propack:3.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:linux:linux_kernel:2.4.22:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23:pre9:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23_ow2:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.24:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.24_ow1:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.25:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.2:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.3:-:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:current:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:2.4.22:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23::-ow2:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.23::-pre9:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.24:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.24::-ow1:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.4.25:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.2:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*
  • OR cpe:/a:sgi:propack:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.1:-:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.3:-:*:*:*:*:*:*
  • AND
  • cpe:/a:suse:suse_linux_database_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_linux_connectivity_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_linux_office_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:current:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:10:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20040424
    V
    CVE-2004-0424
    2015-11-16
    oval:org.mitre.oval:def:11214
    V
    Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.
    2013-04-29
    oval:org.mitre.oval:def:939
    V
    Linux Kernel ip_setsockopt Integer Overflow
    2007-04-25
    oval:com.redhat.rhsa:def:20040183
    P
    RHSA-2004:183: kernel security update (Important)
    2004-04-22
    BACK
    sgi propack 3.0
    linux linux kernel 2.4.22
    linux linux kernel 2.4.23
    linux linux kernel 2.4.23 pre9
    linux linux kernel 2.4.23_ow2
    linux linux kernel 2.4.24
    linux linux kernel 2.4.24_ow1
    linux linux kernel 2.4.25
    linux linux kernel 2.6.1
    linux linux kernel 2.6.1 rc1
    linux linux kernel 2.6.1 rc2
    linux linux kernel 2.6.2
    linux linux kernel 2.6.3
    slackware slackware linux 9.1
    slackware slackware linux current
    linux linux kernel 2.4.22
    linux linux kernel 2.4.23
    linux linux kernel 2.4.23
    linux linux kernel 2.4.23
    linux linux kernel 2.4.24
    linux linux kernel 2.4.24
    linux linux kernel 2.4.25
    linux linux kernel 2.6.2
    linux linux kernel 2.6.1 rc2
    linux linux kernel 2.6.1 rc1
    sgi propack 3.0
    linux linux kernel 2.6.1
    linux linux kernel 2.6.3
    suse suse linux database server *
    suse suse linux connectivity server *
    suse suse linux office server *
    suse suse linux 8.1
    mandrakesoft mandrake multi network firewall 8.2
    slackware slackware linux current
    mandrakesoft mandrake linux corporate server 2.1
    mandrakesoft mandrake linux 9.1
    trustix secure linux 2.0
    slackware slackware linux 9.1
    suse suse linux 9.0
    mandrakesoft mandrake linux 9.2
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    trustix secure linux 2.1
    mandrakesoft mandrake linux 10.0
    conectiva linux 10
    mandrakesoft mandrake linux 9.1
    mandrakesoft mandrake linux 9.2
    mandrakesoft mandrake linux corporate server 2.1