LOW · 2.1

CVE-2004-0535

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally i...

Vulnerability Description

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MandrakesoftMandrake Multi Network Firewall8.2
SuseSuse Email Server3.1
SuseSuse Linux Admin-Cd For FirewallAll versions
SuseSuse Linux Connectivity ServerAll versions
SuseSuse Linux Database ServerAll versions
SuseSuse Linux Firewall CdAll versions
SuseSuse Linux Firewall Live-CdAll versions
SuseSuse Linux Office ServerAll versions
SuseSuse Office ServerAll versions
ConectivaLinux8.0
EngardelinuxSecure Community2.0
EngardelinuxSecure Linux1.5
GentooLinux1.4
LinuxLinux Kernel2.4.0
MandrakesoftMandrake Linux9.1
MandrakesoftMandrake Linux Corporate Server2.1
SuseSuse Linux7

References

FAQ

What is CVE-2004-0535?

CVE-2004-0535 is a vulnerability with a CVSS score of 2.1 (LOW). The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally i...

How severe is CVE-2004-0535?

CVE-2004-0535 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0535?

Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Multi Network Firewall, Suse Suse Email Server, Suse Suse Linux Admin-Cd For Firewall, Suse Suse Linux Connectivity Server, Suse Suse Linux Database Server.