The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-0412
http://www.kb.cert.org/vuls/id/471084
http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt