Vulnerability Description
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| The Pax Team | Pax Linux | 2.6.5 |
| Gentoo | Linux | 1.4 |
References
- http://marc.info/?l=bugtraq&m=108360001130312&w=2
- http://marc.info/?l=bugtraq&m=108420555920369&w=2
- http://pax.grsecurity.net/Patch
- http://security.gentoo.org/glsa/glsa-200407-02.xmlVendor Advisory
- http://www.securityfocus.com/bid/10264ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16037
- http://marc.info/?l=bugtraq&m=108360001130312&w=2
- http://marc.info/?l=bugtraq&m=108420555920369&w=2
- http://pax.grsecurity.net/Patch
- http://security.gentoo.org/glsa/glsa-200407-02.xmlVendor Advisory
- http://www.securityfocus.com/bid/10264ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16037
FAQ
What is CVE-2004-1983?
CVE-2004-1983 is a vulnerability with a CVSS score of 2.1 (LOW). The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infin...
How severe is CVE-2004-1983?
CVE-2004-1983 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1983?
Check the references section above for vendor advisories and patch information. Affected products include: The Pax Team Pax Linux, Gentoo Linux.