Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-1333

CWE-13335 documents5 sources
Severity
2.1LOW
EPSS
0.2%
top 58.30%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 15
Latest updateMay 2

Description

Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages3 packages

NVDlinux/linux_kernel43 versions+42
NVDredhat/linux7.3, 9.0+1
NVDredhat/fedora_corecore_1.0, core_2.0, core_3.0+2

Patches

🔴Vulnerability Details

3
GHSA
Spring Framework Inefficient Regular Expression Complexity2022-05-02
GHSA
GHSA-jhcc-2gg3-8q6c: Integer overflow in the vc_resize function in the Linux kernel 22022-04-29
CVEList
CVE-2004-1333: Integer overflow in the vc_resize function in the Linux kernel 22005-01-06

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel 2.4.28/2.6.9 - vc_resize int Local Overflow2004-12-16
CVE-2004-1333 (LOW CVSS 2.1) | Integer overflow in the vc_resize f | cvebase.io