CVE-2004-0177
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.
El código ext3 en Linux 2.4.x no inicializa adecuadamente bloques de descriptores de diario, lo que causa una fuga de información en la que datos de memoria son escritos en el dispositivo de un sistema de ficheros ext3, lo que permite a usuarios privilegiados obtener porciones de la memoria del kernel leyendo directamente del dispositivo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-02-25 CVE Reserved
- 2004-04-16 CVE Published
- 2024-08-08 CVE Updated
- 2024-09-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (26)
URL | Tag | Source |
---|---|---|
http://linux.bkbits.net:8080/linux-2.4/cset%404056b368s6vpJbGWxDD_LhQNYQrdzQ | X_refsource_misc | |
http://www.ciac.org/ciac/bulletins/o-121.shtml | Government Resource | |
http://www.ciac.org/ciac/bulletins/o-126.shtml | Government Resource | |
http://www.ciac.org/ciac/bulletins/o-127.shtml | Government Resource | |
http://www.securityfocus.com/bid/10152 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15867 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10556 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2004-166.html | 2023-11-07 | |
http://www.debian.org/security/2004/dsa-495 | 2023-11-07 | |
http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.4.0 Search vendor "Linux" for product "Linux Kernel" and version "2.4.0" | - |
Affected
|