CVE-2005-4618

Linux Kernel <2.6.15 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

References (13)

Core 13
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:040
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19369
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1018
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16141
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0035
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18216
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1017
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/244-1/
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18527
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19374

Scores

EPSS 0.0045
EPSS Percentile 37.3%

Details

Status published
Products (26)
linux/linux_kernel 2.6.0 (12 CPE variants)
linux/linux_kernel 2.6.1 (3 CPE variants)
linux/linux_kernel 2.6.2
linux/linux_kernel 2.6.3
linux/linux_kernel 2.6.4
linux/linux_kernel 2.6.5
linux/linux_kernel 2.6.6 (2 CPE variants)
linux/linux_kernel 2.6.7 (2 CPE variants)
linux/linux_kernel 2.6.8 (4 CPE variants)
linux/linux_kernel 2.6.9 2.6.20
... and 16 more
Published Dec 31, 2005
Tracked Since Feb 18, 2026