CVE-2004-0075
https://notcve.org/view.php?id=CVE-2004-0075
The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service. El controlador USB Vicam de Linux 2.5.25 no utiliza la función copy_from_user cuando copia datos de espacio de usuario a espacio de kernel, lo que traspasa límites de seguridad y permite a usuarios locales causar una denegación de servicio. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846 http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015 http://www.ciac.org/ciac/bulletins/o-082.shtml http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html http://www.redhat.com/support/errata/RHSA-2004-065.html http://www.redhat.com/support/errata/RHSA-2005-293.html http://www.securityfocus.com/bid/9690 https://exchange.xforce.ibmcloud.com/vulnerabilities/15246 https://oval.cise •
CVE-2002-1574
https://notcve.org/view.php?id=CVE-2002-1574
Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors. Desbordamiento de búfer en el controlador de tarjeta de telefónica ixj en Linux anteriores a 2.4.20 tiene vectores de ataque e impacto desconocidos. • http://www.ciac.org/ciac/bulletins/n-096.shtml http://www.redhat.com/support/errata/RHSA-2002-205.html http://www.redhat.com/support/errata/RHSA-2002-206.html http://www.redhat.com/support/errata/RHSA-2004-044.html http://www.redhat.com/support/errata/RHSA-2004-106.html http://www.securityfocus.com/bid/5985 https://exchange.xforce.ibmcloud.com/vulnerabilities/10417 https://access.redhat.com/security/cve/CVE-2002-1574 https://bugzilla.redhat.com/show_bug.cgi?id=161692 •
CVE-2004-2136
https://notcve.org/view.php?id=CVE-2004-2136
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption. • http://marc.info/?l=linux-kernel&m=107719798631935&w=2 http://mareichelt.de/pub/notmine/diskenc.pdf http://www.securiteam.com/exploits/5UP0P1PFPM.html •
CVE-2004-0010
https://notcve.org/view.php?id=CVE-2004-0010
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges. Vulnerabilidad desconocida en la función ncp_lookup de ncpfs en Red Hat Enterprese Linux 2.1 permite a usuarios locales ganar privilegios. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820 http://fedoranews.org/updates/FEDORA-2004-079.shtml http://www.ciac.org/ciac/bulletins/o-082.shtml http://www.debian.org/security/2004/dsa-479 http://www.debian.org/security/2004/dsa-480 http://www.debian.org/security/2004/dsa-481 http://www.debian.org/security/2004/dsa-482 http://www.debian.org/security/2004/dsa-489 http://www.debian.org/security/2004/dsa-491 http://www.debian.org/secu •
CVE-2004-0077 – Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2004-0077
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985. La función do_remap en mremap de Linux 2.2 a 2.2.25, 2.4 a 2.4.24, y 2.6 a 2.6.2 no comprueba adecuadamente el valor devuelto por la función do_munmap cuando se excede el número máximo de descriptores VMA, lo que permite a usuarios locales ganar privilegios de root, una vulnerabilidad distinta de CAN-2004-0985. A critical security vulnerability has been found in the Linux kernel memory management code inside the mremap(2) system call due to missing function return value check. This bug is completely unrelated to the mremap bug disclosed on 05-01-2004 except concerning the same internal kernel function code. Versions affected: 2.2 up to 2.2.25, 2.4 up to 2.4.24, 2.6 up to 2.6.2. • https://www.exploit-db.com/exploits/160 https://www.exploit-db.com/exploits/154 http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820 http://fedoranews.org/updates/FEDORA-2004-079.shtml http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015 http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt http://marc.info/?l=bugtraq&m=107711762014175&w=2 http://marc.info/?l=bugtraq&m=10771 •