CVE-2004-0685

5 documents5 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 64.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateApr 29

Description

Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

NVDlinux/linux_kernel139 versions+138
NVDtrustix/secure_linux2.0, 2.1+1

Also affects: Enterprise Linux 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vrc6-2fg4-xjqm: Certain USB drivers in the Linux 22022-04-29
CVEList
CVE-2004-0685: Certain USB drivers in the Linux 22004-10-26

📋Vendor Advisories

1
Red Hat
security flaw2003-10-23

💬Community

1
Bugzilla
CVE-2004-0685 security flaw2018-08-16
CVE-2004-0685 (MEDIUM CVSS 4.6) | Certain USB drivers in the Linux 2. | cvebase.io