CVE-2004-0685

Scores

EPSS

0.001very_low0.1%
0%20%40%60%80%100%

Percentile: 0.1%

CVSS

4.6medium2.0
0246810

CVSS Score: 4.6/10

All CVSS Scores

CVSS 2.0
4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Description

Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

Recommendations

Source: nvd

Check with VendorUsers who suspect they are vulnerable are encouraged to check with their vendor to determine the appropriate action to take.Upgrade to Unaffected Build of the Linux KernelUsers are encouraged to upgrade to an unaffected build of the Linux kernel.

URL: http://www.kb.cert.org/vuls/id/981134

Vulnerable Software (6)

Type: Configuration

Product: kernel

Operating System: rhel 3

Trait:
{  "fixed": "2.4.21-20.0.1.EL"}

Source: redhat

Type: Configuration

Product: kernel-source-2.4.27

Operating System: debian

Trait:
{  "fixed": "2.4.27-1"}

Source: debian

Type: Configuration

Vendor: linux

Product: linux_kernel

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.1:*:*:*:*:*:*:*...

Source: nvd

Type: Configuration

Vendor: redhat

Product: enterprise_linux

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.1:*:*:*:*:*:*:*...

Source: nvd

Type: Configuration

Vendor: redhat

Product: enterprise_linux_desktop

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.1:*:*:*:*:*:*:*...

Source: nvd

Type: Configuration

Vendor: trustix

Product: secure_linux

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:linux:linux_kernel:2.2.1:*:*:*:*:*:*:*...

Source: nvd