VulnerabilityModified
CVE-2003-0418
The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
MEDIUM 5.0EPSS 2.83%
Does this matter?
Lower severity and a low EPSS score (2.83%). Track it; it rarely justifies an emergency change on its own.
Description
The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.83% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105519179005065&w=2
- http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txtExploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/471084Patch, Third Party Advisory, US Government Resource
- http://marc.info/?l=bugtraq&m=105519179005065&w=2
- http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txtExploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/471084Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.