SB2003082701 - Integer overflow in Linux kernel
Published: August 27, 2003 Updated: August 7, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2003-0619)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
Remediation
Install update from vendor's website.