CVE-2004-1137

Linux Kernel - Denial of Service

Title source: rule

Description

Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Paul Starzetz · cdoslinux
https://www.exploit-db.com/exploits/686

Scores

EPSS 0.1582
EPSS Percentile 94.6%

Classification

Status draft

Affected Products (50)

linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Jan 10, 2005
Tracked Since Feb 18, 2026