CVE-2004-0109

Linux Kernel 2.4.x-2.6.x - Local Buffer Overflow via Malformed ISO9660 Symbolic Link

Title source: llm
STIX 2.1

Description

Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

References (42)

Core 42
Core References
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15866
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11626
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11464
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-105.html
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-127.shtml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11518
Patch, Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
Mailing List vendor-advisory x_refsource_trustix
http://marc.info/?l=bugtraq&m=108213675028441&w=2
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-482
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11861
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11362
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A940
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-495
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-183.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-479
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12003
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11891
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_09_kernel.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11469
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11486
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10733
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-480
Various Sources vendor-advisory x_refsource_turbo
http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10141
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11986
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11470
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11361
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-489
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-481
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11373
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
Patch, Vendor Advisory vendor-advisory x_refsource_engarde
http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-106.html
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-121.shtml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11429
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11494
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200407-02.xml
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2004-166.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-491

Scores

EPSS 0.0056
EPSS Percentile 43.5%

Details

Status published
Products (3)
linux/linux_kernel 2.4.0
linux/linux_kernel 2.5.0
linux/linux_kernel 2.6.0
Published Jun 01, 2004
Tracked Since Feb 18, 2026