LOW · 2.1

CVE-2004-0565

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processe...

Vulnerability Description

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MandrakesoftMandrake Multi Network Firewall8.2
GentooLinuxAll versions
LinuxLinux Kernel2.4.0
MandrakesoftMandrake Linux9.1
MandrakesoftMandrake Linux Corporate Server2.1
TrustixSecure Linux2

References

FAQ

What is CVE-2004-0565?

CVE-2004-0565 is a vulnerability with a CVSS score of 2.1 (LOW). Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processe...

How severe is CVE-2004-0565?

CVE-2004-0565 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0565?

Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Multi Network Firewall, Gentoo Linux, Linux Linux Kernel, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server.