First published: Tue Jun 15 2004(Updated: )
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | =2.6.5 | |
Linux Kernel | =2.6.1 | |
SUSE Linux | =9.0 | |
Linux Kernel | =2.4.26 | |
SUSE Linux | =8.2 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
SUSE Linux | =8 | |
Linux Kernel | =2.6.3 | |
Linux Kernel | =2.6.4 | |
Red Hat Enterprise Linux | =2.1 | |
Linux Kernel | =2.6.7-rc1 | |
Linux Kernel | =2.4.21 | |
SUSE Linux | =9.0 | |
Linux Kernel | =2.4.23 | |
Linux Kernel | =2.6.2 | |
Avaya Modular Messaging Message Storage Server | =s3400 | |
Linux Kernel | =2.6.1-rc2 | |
Linux Kernel | =2.4.25 | |
Linux Kernel | =2.4.24 | |
avaya converged communications server | =2.0 | |
SUSE Linux | =8.0 | |
Linux Kernel | =2.6.0 | |
SUSE Linux | =7 | |
Linux Kernel | =2.4.19 | |
SUSE Linux | =8.0 | |
SUSE Linux | =9.1 | |
Red Hat Enterprise Linux | =3.0 | |
Linux Kernel | =2.4.22 | |
Red Hat Enterprise Linux | =2.1 | |
Linux Kernel | =2.6.7 | |
Gentoo Linux | =1.4 | |
Linux Kernel | =2.6.1-rc1 | |
Linux Kernel | =2.4.18 | |
Linux Kernel | =2.6.6-rc1 | |
Red Hat Enterprise Linux | =3.0 | |
SUSE Linux | =8.1 | |
Linux Kernel | =2.6.6 | |
Avaya S8500 | =r2.0.1 | |
Conectiva Linux | =9.0 | |
Avaya S8300 | =r2.0.0 | |
Avaya Intuity Audix | ||
Conectiva Linux | =8.0 | |
Emailarchitect Email Server | =3.1 | |
SUSE Linux Database Server | ||
avaya s8700 | =r2.0.1 | |
SUSE SUSE Linux Firewall | ||
SUSE Office Server | ||
SUSE Office Server | ||
avaya s8700 | =r2.0.0 | |
SUSE Linux Connectivity Server | ||
Emailarchitect Email Server | =iii | |
Avaya S8500 | =r2.0.0 | |
SUSE SUSE Linux Firewall | ||
Avaya S8300 | =r2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0554 is considered a high severity vulnerability due to its potential to cause a denial of service and system crash.
To fix CVE-2004-0554, you should update the Linux kernel to the latest version that addresses this vulnerability.
CVE-2004-0554 affects Linux kernel versions 2.4.x and 2.6.x, including various distributions like Red Hat, SUSE, and Gentoo.
Local users can exploit CVE-2004-0554 by executing a program that triggers an infinite loop with specific fsave and frstor instruction sequences.
CVE-2004-0554 facilitates a denial of service attack by causing the affected system to crash.