SB2001050302 - Integer underflow in Linux kernel
Published: May 3, 2001 Updated: November 7, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2001-0316)
The vulnerability allows a local user to read and manipulate data.
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.
Remediation
Install update from vendor's website.
References
- http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html
- http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt
- http://www.osvdb.org/6017
- http://www.redhat.com/support/errata/RHSA-2001-013.html
- http://www.securityfocus.com/bid/2364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6079