CVE-2004-1190
published 2005-01-10CVE-2004-1190: SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.40%
31.8th percentile
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Framework Inefficient Regular Expression Complexity
ghsa·2022-05-02·CVSS 5.0
CVE-2009-1190 [MEDIUM] CWE-1333 Spring Framework Inefficient Regular Expression Complexity
Spring Framework Inefficient Regular Expression Complexity
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
GHSA
GHSA-6q77-qw67-r7r7: SUSE Linux before 9
ghsa_unreviewed·2022-04-29
CVE-2004-1190 [LOW] GHSA-6q77-qw67-r7r7: SUSE Linux before 9
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.
Red Hat
Spring Framework Remote Denial of Service vulnerability
vendor_redhat·2009-04-22·CVSS 5.0
CVE-2009-1190 [MEDIUM] Spring Framework Remote Denial of Service vulnerability
Spring Framework Remote Denial of Service vulnerability
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
Statement: This flaw affected JBoss Enterprise BRMS Platform 5.1.0 when run on Sun JDK 1.5.x. It was resolved in JBoss Enterprise BRMS Platform 5.2.0, both by updating spring and by dropping support for Sun JDK 1.5.x.
Red Hat
security flaw
vendor_redhat·2004-07-30·CVSS 2.1
CVE-2004-1190 [LOW] security flaw
security flaw
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1190 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2004-1190 [LOW] CVE-2004-1190 security flaw
CVE-2004-1190 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.
Bugzilla
CVE-2004-1190 Continued raw access issues
bugzilla·2005-05-26·CVSS 2.1
CVE-2004-1190 [LOW] CVE-2004-1190 Continued raw access issues
CVE-2004-1190 Continued raw access issues
CAN-2004-0813 described a flaw allowing anyone with read access to scsi hardware
the ability to write to it too, and this was fixed upstream in 2.6.8. However
since then a number of extra commits have taken place to fix firmware cdrom
issues -- see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=300162
These may affect RHEL4.
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0101.html
http://secunia.com/advisories/18510http://www.novell.com/linux/security/advisories/2004_42_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0101.htmlhttp://www.securityfocus.com/bid/11784https://exchange.xforce.ibmcloud.com/vulnerabilities/18370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9369http://secunia.com/advisories/18510http://www.novell.com/linux/security/advisories/2004_42_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0101.htmlhttp://www.securityfocus.com/bid/11784https://exchange.xforce.ibmcloud.com/vulnerabilities/18370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9369
2005-01-10
Published