PT-2003-2527 · Gentoo+1 · Aa-Sources+1

Published

1970-01-01

·

Updated

2018-05-03

·

CVE-2004-0077

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.2 through 2.2.25 Linux kernel versions 2.4 through 2.4.24 Linux kernel versions 2.6 through 2.6.2 aa-sources versions prior to 2.4.23-r1
Description The issue is related to multiple vulnerabilities in the Linux kernel, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker. The do mremap function for the mremap system call does not properly check the return value from the do munmap function when the maximum number of VMA descriptors is exceeded, allowing local users to gain root privileges.
Recommendations For Linux kernel versions 2.2 through 2.2.25, update to a version outside of this range to resolve the issue. For Linux kernel versions 2.4 through 2.4.24, update to a version outside of this range to resolve the issue. For Linux kernel versions 2.6 through 2.6.2, update to a version outside of this range to resolve the issue. For aa-sources versions prior to 2.4.23-r1, update to version 2.4.23-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable system calls until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02171
BDU:2015-02172
BDU:2015-02173
BDU:2015-02174
BDU:2015-02175
BDU:2015-02176
BDU:2015-02837
BDU:2015-02838
BDU:2015-02839
BDU:2015-02840
BDU:2015-02841
BDU:2015-02842
BDU:2015-02843
BDU:2015-02844
BDU:2015-02845
BDU:2015-02846
BDU:2015-02847
BDU:2015-02848
BDU:2015-02849
BDU:2015-02850
BDU:2015-02851
BDU:2015-02852
BDU:2015-02853
BDU:2015-02854
BDU:2015-02855
BDU:2015-02856
BDU:2015-03283
BDU:2015-03284
BDU:2015-03285
BDU:2015-03286
BDU:2015-03320
BDU:2015-03321
BDU:2015-03322
BDU:2015-03323
BDU:2015-03324
BDU:2015-04101
BDU:2015-04102
BDU:2015-04103
BDU:2015-04104
BDU:2015-04105
BDU:2015-04106
BDU:2015-04107
BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
BDU:2015-09448
CVE-2004-0077
DSA-438
DSA-439
DSA-440
DSA-441
DSA-442
DSA-444
DSA-450
DSA-453
DSA-454
DSA-456
DSA-466
DSA-470
DSA-475
DSA-514
RHSA-2004:066

Affected Products

Linux Kernel
Aa-Sources