Information exposure in Linux kernel - CVE-2005-0176

 

Information exposure in Linux kernel - CVE-2005-0176

Published: February 15, 2005 / Updated: October 11, 2017


Vulnerability identifier: #VU99937
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2005-0176
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.


Affected software

Linux kernel

How to mitigate CVE-2005-0176

Install update from vendor's repository.


External References

Related Security Bulletins