CVE-2004-0424 describes an integer overflow vulnerability in the ip_setsockopt function within specific versions of the Linux kernel (2.4.22-2.4.25 and 2.6.1-2.6.3). This flaw allows local users to trigger a denial of service (system crash) or potentially execute arbitrary code by manipulating the MCAST_MSFILTER socket option. With a CVSS score of 7.2, this vulnerability is considered highly severe, enabling local attackers to achieve complete confidentiality, integrity, and availability compromise with low attack complexity. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists for a local denial of service, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:sgi:propack:3.0:*:*:*:*:*:*:* | ||
2.4.22CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.22:*:*:*:*:*:*:* | ||
2.4.23CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.23:*:*:*:*:*:*:* | ||
2.4.23CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.23:pre9:*:*:*:*:*:* | ||
2.4.23_ow2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.4.23_ow2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.