Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-0482

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2004-0482
Last Modified 05 Sep 2008 04:38:32
Published 07 Jul 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2004-0482

Summary

Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly perform other unauthorized activities.

Vulnerable Systems

Operating System

  • Openbsd 3.4

  • Openbsd 3.5


References

MLIST - [openbsd-security-announce] 20040513 procfs vulnerability

CONFIRM - ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch

CONFIRM - ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch

XF - openbsd-procfs-gain-privileges(16226)

OSVDB - 6114

OPENBSD - 20040513 [3.5] 006: SECURITY FIX: May 13, 2004

OPENBSD - 20040513 [3.4] 020: SECURITY FIX: May 13, 2004

MISC - http://www.deprotect.com/advisories/DEPROTECT-20041305.txt

SECUNIA - 11605

FULLDISC - 20040517 OpenBSD procfs


Last Updated: 27 May 2016 10:38:37