CVE-2003-0418

Linux Kernel 2.0 - Information Disclosure via ICMP Error Response

Title source: llm
STIX 2.1

Description

The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105519179005065&w=2
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/471084
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt

Scores

EPSS 0.0283
EPSS Percentile 85.4%

Details

Status published
Products (40)
linux/linux_kernel 2.0
linux/linux_kernel 2.0.1
linux/linux_kernel 2.0.2
linux/linux_kernel 2.0.3
linux/linux_kernel 2.0.4
linux/linux_kernel 2.0.5
linux/linux_kernel 2.0.6
linux/linux_kernel 2.0.7
linux/linux_kernel 2.0.8
linux/linux_kernel 2.0.9
... and 30 more
Published Jul 24, 2003
Tracked Since Feb 18, 2026