VDB
CVE-2004-1137
CVE-2004-1137
PUBLISHED
Reported by mitre · Published December 15, 2004
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Dec 15, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- oval:org.mitre.oval:def:11144 vdb-entrysignaturex_refsource_OVAL
- MDKSA-2005:022 vendor-advisoryx_refsource_MANDRAKE
- 20041214 [USN-38-1] Linux kernel vulnerabilities mailing-listx_refsource_BUGTRAQ
- FLSA:2336 vendor-advisoryx_refsource_FEDORA
- SUSE-SA:2004:044 vendor-advisoryx_refsource_SUSE
- RHSA-2005:092 vendor-advisoryx_refsource_REDHAT
- CLA-2005:930 vendor-advisoryx_refsource_CONECTIVA
- x_refsource_MISC
- linux-igmpmarksources-dos(18482) vdb-entryx_refsource_XF
- linux-ipmcsource-code-execution(18481) vdb-entryx_refsource_XF