7.2

CVE-2004-1070

The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version 2.4.0
Linux ≫ Linux Kernel Version 2.4.0 Update test1
Linux ≫ Linux Kernel Version 2.4.0 Update test10
Linux ≫ Linux Kernel Version 2.4.0 Update test11
Linux ≫ Linux Kernel Version 2.4.0 Update test12
Linux ≫ Linux Kernel Version 2.4.0 Update test2
Linux ≫ Linux Kernel Version 2.4.0 Update test3
Linux ≫ Linux Kernel Version 2.4.0 Update test4
Linux ≫ Linux Kernel Version 2.4.0 Update test5
Linux ≫ Linux Kernel Version 2.4.0 Update test6
Linux ≫ Linux Kernel Version 2.4.0 Update test7
Linux ≫ Linux Kernel Version 2.4.0 Update test8
Linux ≫ Linux Kernel Version 2.4.0 Update test9
Linux ≫ Linux Kernel Version 2.4.1
Linux ≫ Linux Kernel Version 2.4.2
Linux ≫ Linux Kernel Version 2.4.3
Linux ≫ Linux Kernel Version 2.4.4
Linux ≫ Linux Kernel Version 2.4.5
Linux ≫ Linux Kernel Version 2.4.6
Linux ≫ Linux Kernel Version 2.4.7
Linux ≫ Linux Kernel Version 2.4.8
Linux ≫ Linux Kernel Version 2.4.9
Linux ≫ Linux Kernel Version 2.4.10
Linux ≫ Linux Kernel Version 2.4.11
Linux ≫ Linux Kernel Version 2.4.12
Linux ≫ Linux Kernel Version 2.4.13
Linux ≫ Linux Kernel Version 2.4.14
Linux ≫ Linux Kernel Version 2.4.15
Linux ≫ Linux Kernel Version 2.4.16
Linux ≫ Linux Kernel Version 2.4.17
Linux ≫ Linux Kernel Version 2.4.18
Linux ≫ Linux Kernel Version 2.4.18 Edition x86
Linux ≫ Linux Kernel Version 2.4.18 Update pre1
Linux ≫ Linux Kernel Version 2.4.18 Update pre2
Linux ≫ Linux Kernel Version 2.4.18 Update pre3
Linux ≫ Linux Kernel Version 2.4.18 Update pre4
Linux ≫ Linux Kernel Version 2.4.18 Update pre5
Linux ≫ Linux Kernel Version 2.4.18 Update pre6
Linux ≫ Linux Kernel Version 2.4.18 Update pre7
Linux ≫ Linux Kernel Version 2.4.18 Update pre8
Linux ≫ Linux Kernel Version 2.4.19
Linux ≫ Linux Kernel Version 2.4.19 Update pre1
Linux ≫ Linux Kernel Version 2.4.19 Update pre2
Linux ≫ Linux Kernel Version 2.4.19 Update pre3
Linux ≫ Linux Kernel Version 2.4.19 Update pre4
Linux ≫ Linux Kernel Version 2.4.19 Update pre5
Linux ≫ Linux Kernel Version 2.4.19 Update pre6
Linux ≫ Linux Kernel Version 2.4.20
Linux ≫ Linux Kernel Version 2.4.21
Linux ≫ Linux Kernel Version 2.4.21 Update pre1
Linux ≫ Linux Kernel Version 2.4.21 Update pre4
Linux ≫ Linux Kernel Version 2.4.21 Update pre7
Linux ≫ Linux Kernel Version 2.4.22
Linux ≫ Linux Kernel Version 2.4.23
Linux ≫ Linux Kernel Version 2.4.23 Update pre9
Linux ≫ Linux Kernel Version 2.4.23_ow2
Linux ≫ Linux Kernel Version 2.4.24
Linux ≫ Linux Kernel Version 2.4.24_ow1
Linux ≫ Linux Kernel Version 2.4.25
Linux ≫ Linux Kernel Version 2.4.26
Linux ≫ Linux Kernel Version 2.4.27
Linux ≫ Linux Kernel Version 2.4.27 Update pre1
Linux ≫ Linux Kernel Version 2.4.27 Update pre2
Linux ≫ Linux Kernel Version 2.4.27 Update pre3
Linux ≫ Linux Kernel Version 2.4.27 Update pre4
Linux ≫ Linux Kernel Version 2.4.27 Update pre5
Linux ≫ Linux Kernel Version 2.6.0
Linux ≫ Linux Kernel Version 2.6.0 Update test1
Linux ≫ Linux Kernel Version 2.6.0 Update test10
Linux ≫ Linux Kernel Version 2.6.0 Update test11
Linux ≫ Linux Kernel Version 2.6.0 Update test2
Linux ≫ Linux Kernel Version 2.6.0 Update test3
Linux ≫ Linux Kernel Version 2.6.0 Update test4
Linux ≫ Linux Kernel Version 2.6.0 Update test5
Linux ≫ Linux Kernel Version 2.6.0 Update test6
Linux ≫ Linux Kernel Version 2.6.0 Update test7
Linux ≫ Linux Kernel Version 2.6.0 Update test8
Linux ≫ Linux Kernel Version 2.6.0 Update test9
Linux ≫ Linux Kernel Version 2.6.1
Linux ≫ Linux Kernel Version 2.6.1 Update rc1
Linux ≫ Linux Kernel Version 2.6.1 Update rc2
Linux ≫ Linux Kernel Version 2.6.2
Linux ≫ Linux Kernel Version 2.6.3
Linux ≫ Linux Kernel Version 2.6.4
Linux ≫ Linux Kernel Version 2.6.5
Linux ≫ Linux Kernel Version 2.6.6
Linux ≫ Linux Kernel Version 2.6.6 Update rc1
Linux ≫ Linux Kernel Version 2.6.7
Linux ≫ Linux Kernel Version 2.6.7 Update rc1
Linux ≫ Linux Kernel Version 2.6.8
Linux ≫ Linux Kernel Version 2.6.8 Update rc1
Linux ≫ Linux Kernel Version 2.6.8 Update rc2
Linux ≫ Linux Kernel Version 2.6.8 Update rc3
Linux ≫ Linux Kernel Version 2.6.9 Update 2.6.20
Linux ≫ Linux Kernel Version 2.6_test9_cvs
Redhat ≫ Enterprise Linux Version 2.1 Edition advanced_server
Redhat ≫ Enterprise Linux Version 2.1 Edition advanced_server_ia64
Redhat ≫ Enterprise Linux Version 2.1 Edition enterprise_server
Redhat ≫ Enterprise Linux Version 2.1 Edition enterprise_server_ia64
Redhat ≫ Enterprise Linux Version 2.1 Edition workstation
Redhat ≫ Enterprise Linux Version 2.1 Edition workstation_ia64
Redhat ≫ Enterprise Linux Version 3.0 Edition advanced_server
Redhat ≫ Enterprise Linux Version 3.0 Edition enterprise_server
Redhat ≫ Enterprise Linux Version 3.0 Edition workstation_server
Redhat ≫ Fedora Core Version core_2.0
Redhat ≫ Fedora Core Version core_3.0
Redhat ≫ Linux Advanced Workstation Version 2.1 Edition ia64
Redhat ≫ Linux Advanced Workstation Version 2.1 Edition itanium_processor
Suse ≫ Suse Linux Version 1.0 Edition desktop
Suse ≫ Suse Linux Version 8 Edition enterprise_server
Suse ≫ Suse Linux Version 8.1
Suse ≫ Suse Linux Version 8.2
Suse ≫ Suse Linux Version 9.0
Suse ≫ Suse Linux Version 9.0 Edition enterprise_server
Suse ≫ Suse Linux Version 9.0 Edition x86_64
Suse ≫ Suse Linux Version 9.1
Suse ≫ Suse Linux Version 9.2
Trustix ≫ Secure Linux Version 1.5
Trustix ≫ Secure Linux Version 2.0
Trustix ≫ Secure Linux Version 2.1
Trustix ≫ Secure Linux Version 2.2
Turbolinux ≫ Turbolinux Server Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.392
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20162
Vendor Advisory
http://secunia.com/advisories/20163
Vendor Advisory
http://secunia.com/advisories/20202
Vendor Advisory
http://secunia.com/advisories/20338
Vendor Advisory
http://www.debian.org/security/2006/dsa-1067
http://www.debian.org/security/2006/dsa-1069
http://www.debian.org/security/2006/dsa-1070
http://www.debian.org/security/2006/dsa-1082
http://www.redhat.com/support/errata/RHSA-2004-504.html
http://www.redhat.com/support/errata/RHSA-2004-505.html
https://bugzilla.fedora.us/show_bug.cgi?id=2336
http://www.redhat.com/support/errata/RHSA-2004-549.html
http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U
http://secunia.com/advisories/19607
Vendor Advisory
http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt
http://www.securityfocus.com/bid/11646
https://exchange.xforce.ibmcloud.com/vulnerabilities/18025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9450