Vulnerability Name:

CVE-2004-0626 (CCN-16554)

Assigned:2004-06-30
Published:2004-06-30
Updated:2017-07-11
Summary:The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Wed Jun 30 2004 - 05:57:17 CDT
Remote DoS vulnerability in Linux kernel 2.6.x

Source: MITRE
Type: CNA
CVE-2004-0626

Source: CONECTIVA
Type: Patch, Vendor Advisory
CLA-2004:852

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2004:852
Fixes for kernel vulnerabilities

Source: FEDORA
Type: Patch, Vendor Advisory
FEDORA-2004-202

Source: BUGTRAQ
Type: UNKNOWN
20040630 Remote DoS vulnerability in Linux kernel 2.6.x

Source: CCN
Type: GLSA-200407-12
Linux Kernel: Remote DoS vulnerability with IPTables TCP Handling

Source: GENTOO
Type: Patch, Vendor Advisory
GLSA-200407-12

Source: SUSE
Type: UNKNOWN
SUSE-SA:2004:020

Source: CCN
Type: OSVDB ID: 27906
SUSE Linux IPv6 netfilter Subsystem tcp_find_option CPU Consumption DOS

Source: CCN
Type: OSVDB ID: 7316
Linux Kernel Netfilter TCP Option Matching DoS

Source: CCN
Type: BID-10634
Linux Kernel IPTables Sign Error Denial Of Service Vulnerability

Source: XF
Type: UNKNOWN
linux-tcpfindoption-dos(16554)

Source: XF
Type: UNKNOWN
linux-tcpfindoption-dos(16554)

Source: SUSE
Type: SUSE-SA:2004:020
kernel: local privilege escalation

Vulnerable Configuration:Configuration 1:
  • cpe:/o:conectiva:linux:10:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:2.6.0:-:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:2.6.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:suse:suse_linux_database_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_email_server:iii:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_linux_connectivity_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_linux_office_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:10:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20040626
    V
    CVE-2004-0626
    2015-11-16
    BACK
    conectiva linux 10
    gentoo linux *
    linux linux kernel 2.6.0
    suse suse linux 8.0
    suse suse linux 8.1
    suse suse linux 8.2
    suse suse linux 9.0
    suse suse linux 9.1
    linux linux kernel 2.6.0
    suse suse linux database server *
    suse suse email server iii
    suse suse linux connectivity server *
    suse suse linux 8.0
    gentoo linux *
    suse suse linux office server *
    suse suse linux 8.1
    suse suse linux 8.2
    suse suse linux 9.0
    suse suse linux 9.1
    conectiva linux 10