CVE-2004-0228

Current Description

Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.

Basic Data

PublishedAugust 18, 2004
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score7.2
SeverityHIGH
Exploitability Score3.9
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3OSLinuxLinux Kernel2.6.0*******

Vulnerable Software List

VendorProductVersions
Linux Linux Kernel 2.6.0

References

NameSourceURLTags
CLA-2004:852http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852CONECTIVA
FEDORA-2004-111http://fedoranews.org/updates/FEDORA-2004-111.shtmlFEDORA
11429http://secunia.com/advisories/11429SECUNIA
11464http://secunia.com/advisories/11464SECUNIA
11486http://secunia.com/advisories/11486SECUNIA
11491http://secunia.com/advisories/11491SECUNIA
11683http://secunia.com/advisories/11683SECUNIA
GLSA-200407-02http://security.gentoo.org/glsa/glsa-200407-02.xmlGENTOOVendor Advisory
MDKSA-2004:050http://www.mandriva.com/security/advisories?name=MDKSA-2004:050MANDRAKE
SuSE-SA:2004:010http://www.novell.com/linux/security/advisories/2004_10_kernel.htmlSUSE
linux-cpufreq-info-disclosure(15951)https://exchange.xforce.ibmcloud.com/vulnerabilities/15951XF