CVE-2004-0685
published 2004-12-23CVE-2004-0685: Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive…
PriorityP49medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.48%
38.1th percentile
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
Affected
143 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2003-10-23·CVSS 4.6
CVE-2004-0685 [MEDIUM] security flaw
security flaw
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
GHSA
GHSA-vrc6-2fg4-xjqm: Certain USB drivers in the Linux 2
ghsa_unreviewed·2022-04-29
CVE-2004-0685 [MEDIUM] GHSA-vrc6-2fg4-xjqm: Certain USB drivers in the Linux 2
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
No detection rules found.
No public exploits indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.gentoo.org/security/en/glsa/glsa-200408-24.xmlhttp://www.kb.cert.org/vuls/id/981134http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.securityfocus.com/bid/10892http://www.securityspace.com/smysecure/catid.html?id=14580http://www.trustix.net/errata/2004/0041/https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/16931https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10665http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921http://secunia.com/advisories/20162http://secunia.com/advisories/20163http://secunia.com/advisories/20202http://secunia.com/advisories/20338http://www.debian.org/security/2006/dsa-1067http://www.debian.org/security/2006/dsa-1069http://www.debian.org/security/2006/dsa-1070http://www.debian.org/security/2006/dsa-1082http://www.gentoo.org/security/en/glsa/glsa-200408-24.xmlhttp://www.kb.cert.org/vuls/id/981134http://www.redhat.com/support/errata/RHSA-2004-504.htmlhttp://www.redhat.com/support/errata/RHSA-2004-505.htmlhttp://www.securityfocus.com/bid/10892http://www.securityspace.com/smysecure/catid.html?id=14580http://www.trustix.net/errata/2004/0041/https://bugzilla.fedora.us/show_bug.cgi?id=2336https://exchange.xforce.ibmcloud.com/vulnerabilities/16931https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10665
2004-12-23
Published