Candidate: CVE-2004-0447 References: MLIST:[owl-users] 20040619 Linux 2.4.26-ow2 URL:http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html GENTOO:GLSA-200407-16 URL:http://security.gentoo.org/glsa/glsa-200407-16.xml REDHAT:RHSA-2004:413 URL:http://www.redhat.com/support/errata/RHSA-2004-413.html SGI:20040804-01-U URL:ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc CIAC:O-193 URL:http://www.ciac.org/ciac/bulletins/o-193.shtml BID:10783 URL:http://www.securityfocus.com/bid/10783 XF:linux-ia64-dos(16661) URL:http://xforce.iss.net/xforce/xfdb/16661 Description: Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact. NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477. This is the proper candidate to use for the Linux local DoS. Notes: jmm> I've verified that the patch from David Mosberger available at jmm> http://marc.theaimsgroup.com/?l=linux-ia64&m=108026377907667&w=2 jmm> is included in stock 2.4.27 and 2.6.8, so it's N/A. Bugs: upstream: linux-2.6: N/A 2.6.8-sarge-security: N/A 2.4.27-sarge-security: N/A 2.4.19-woody-security: released (2.4.19-4.woody3) 2.4.18-woody-security: released (2.4.18-14.4) 2.4.17-woody-security: released (2.4.17-1woody4) 2.4.16-woody-security: released (2.4.16-1woody3) 2.4.17-woody-security-hppa: released (32.5) 2.4.17-woody-security-ia64: released (011226.18) 2.4.18-woody-security-hppa: released (62.4)