CVE-2004-0535

Published Aug 6, 2004

Last updated 8 days ago

Overview

Description
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
Source
cve@mitre.org
NVD status
Modified
Products
mandrake_multi_network_firewall, suse_email_server, suse_linux_admin-cd_for_firewall, suse_linux_connectivity_server, suse_linux_database_server, suse_linux_firewall_cd, suse_linux_firewall_live-cd, suse_linux_office_server, suse_office_server, linux, secure_community, secure_linux, linux, linux_kernel, mandrake_linux, mandrake_linux_corporate_server, suse_linux

Risk scores

CVSS 2.0

Type
Primary
Base score
2.1
Impact score
2.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.