Improper input validation in Linux kernel - CVE-2004-0495

 

Improper input validation in Linux kernel - CVE-2004-0495

Published: August 6, 2004 / Updated: October 11, 2017


Vulnerability identifier: #VU95481
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2004-0495
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to execute arbitrary code.

Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.


How to mitigate CVE-2004-0495

Install update from vendor's repository.

Sources