Linux Kernel IEEE 1394 Driver Integer Overflow06/28/2004 04:49 PM “infamous41md has reported some vulnerabilities in the Linux
kernel, which potentially can be exploited by malicious, local users
to cause a DoS (Denial of Service) or gain escalated privileges.
Various functions in the IEEE 1394 driver contain integer overflows
within the memory allocation scheme. This can potentially be exploited
via specially crafted requests, which may cause a large amount of data
to be copied into an insufficiently sized buffer.”
Re: [Full-Disclosure] Linux Kernel sctp_setsockopt() Integer Overflow