CVE-2005-2709
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.
- Affected products
- Linux Kernel, Red Hat
- Linux Linux Kernel
- ≤ 2.6.14, 2.2.27, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 2.4.10, 2.4.11, 2.4.12, 2.4.13, 2.4.14, 2.4.15, 2.4.16, 2.4.17, 2.4.18, 2.4.19, 2.4.20, 2.4.21, 2.4.22, 2.4.23, 2.4.24, 2.4.25, 2.4.26, 2.4.27, 2.4.28, 2.4.29, 2.4.30, 2.4.31, 2.4.32, 2.4.33, 2.4.33.1, 2.4.33.2, 2.4.33.3, 2.4.33.4, 2.4.33.5
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2005-11-20
CVE-2005-2709 at NVD
2 known exploits for CVE-2005-2709
Proof-of-concept code and exploit modules indexed by Sploitus