Vulnerability Description
The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.4.0 |
References
- http://seclists.org/lists/linux-kernel/2004/Dec/3914.html
- http://seclists.org/lists/linux-kernel/2005/Jan/1089.html
- http://seclists.org/lists/linux-kernel/2005/Jan/2018.htmlVendor Advisory
- http://seclists.org/lists/linux-kernel/2005/Jan/2020.html
- http://secunia.com/advisories/17002
- http://secunia.com/advisories/18684
- http://secunia.com/advisories/19374
- http://secunia.com/advisories/20163
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338
- http://securitytracker.com/id?1013018
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
- http://www.debian.org/security/2006/dsa-1070
FAQ
What is CVE-2005-0124?
CVE-2005-0124 is a vulnerability with a CVSS score of 2.1 (LOW). The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via ne...
How severe is CVE-2005-0124?
CVE-2005-0124 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0124?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.