[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0077Date: (C)2004-03-03   (M)2023-12-22


The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
2004-0007
2004-0008
http://marc.info/?l=bugtraq&m=107711762014175&w=2
OSVDB-3986
BID-9686
CLA-2004:820
DSA-438
DSA-439
DSA-440
DSA-441
DSA-442
DSA-444
DSA-450
DSA-453
DSA-454
DSA-456
DSA-466
DSA-470
DSA-475
DSA-514
FEDORA-2004-079
GLSA-200403-02
MDKSA-2004:015
O-082
RHSA-2004:065
RHSA-2004:066
RHSA-2004:069
RHSA-2004:106
SSA:2004-049
SuSE-SA:2004:005
VU#981222
http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt
linux-mremap-gain-privileges(15244)
oval:org.mitre.oval:def:825
oval:org.mitre.oval:def:837

CPE    99
cpe:/o:linux:linux_kernel:2.6.0:test1
cpe:/o:linux:linux_kernel:2.6.0:test3
cpe:/o:linux:linux_kernel:2.6.0:test2
cpe:/o:linux:linux_kernel:2.6.0:test9
...

© SecPod Technologies