LOW · 2.1

CVE-2005-0003

The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a...

Vulnerability Description

The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
AvayaMn100All versions
AvayaNetwork RoutingAll versions
AvayaConverged Communications Server2.0
AvayaS8710r2.0.0
AvayaModular Messaging Message Storage Server1.1
LinuxLinux Kernel2.4.0
MandrakesoftMandrake Linux9.2
MandrakesoftMandrake Linux Corporate Server2.1
RedhatEnterprise Linux3.0
RedhatEnterprise Linux Desktop3.0
AvayaIntuity AudixAll versions
MandrakesoftMandrake Multi Network Firewall8.2
AvayaS8300r2.0.0
AvayaS8500r2.0.0
AvayaS8700r2.0.0

References

FAQ

What is CVE-2005-0003?

CVE-2005-0003 is a vulnerability with a CVSS score of 2.1 (LOW). The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a...

How severe is CVE-2005-0003?

CVE-2005-0003 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0003?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Mn100, Avaya Network Routing, Avaya Converged Communications Server, Avaya S8710, Avaya Modular Messaging Message Storage Server.