PT-2004-3732 · Linux+1 · Linux Kernel+1

Publicado

1970-01-01

·

Atualizado

2017-10-11

·

CVE-2004-1070

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.x up to 2.4.27 Linux kernel versions 2.6.x up to 2.6.8
Description The issue is related to the load elf binary function in the binfmt elf loader, which does not properly check return values from calls to the kernel read function. This may allow local users to modify sensitive memory in a setuid program and execute arbitrary code. Multiple vulnerabilities in various kernel packages of the Debian GNU/Linux operating system can be exploited remotely, leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions 2.4.x up to 2.4.27, update to a version later than 2.4.27 to resolve the issue. For Linux kernel versions 2.6.x up to 2.6.8, update to a version later than 2.6.8 to resolve the issue. As a temporary workaround, consider restricting access to setuid programs to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03380
BDU:2015-03381
BDU:2015-03382
BDU:2015-03383
BDU:2015-03384
BDU:2015-03385
BDU:2015-03576
BDU:2015-03577
CVE-2004-1070
DSA-1067-1
DSA-1069-1
DSA-1070-1
DSA-1082-1
RHSA-2004:549

Produtos afetados

Debian
Linux Kernel