PT-2004-1101 · Gentoo+2 · Aa-Sources Package+3
Published
2004-06-08
·
Updated
2017-10-11
·
CVE-2004-0535
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.4.26
aa-sources package versions prior to 2.4.23-r2 in Gentoo Linux
Description
The issue allows local users to read portions of kernel memory due to improper memory initialization in the e1000 driver. Additionally, multiple vulnerabilities in the aa-sources package may lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited locally.
Recommendations
For Linux kernel versions prior to 2.4.26, update to a version 2.4.26 or later to resolve the issue.
For aa-sources package versions prior to 2.4.23-r2 in Gentoo Linux, update to version 2.4.23-r2 or later to address the vulnerabilities.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gentoo Linux
Linux Kernel
Aa-Sources Package
E1000 Driver