CVE-2004-0814

Linux 2.4.x-2.6.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.

References (11)

Core 11
Core References
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110306397320336&w=2
Issue Tracking vendor-advisory x_refsource_fedora
https://bugzilla.fedora.us/show_bug.cgi?id=2336
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17816
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/379005
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11492
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11491
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-293.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10728

Scores

EPSS 0.0069
EPSS Percentile 49.6%

Details

Status published
Products (36)
linux/linux_kernel 2.2.0
linux/linux_kernel 2.2.1
linux/linux_kernel 2.2.2
linux/linux_kernel 2.2.3
linux/linux_kernel 2.2.7
linux/linux_kernel 2.2.8
linux/linux_kernel 2.2.9
linux/linux_kernel 2.2.10
linux/linux_kernel 2.2.11
linux/linux_kernel 2.2.12
... and 26 more
Published Dec 23, 2004
Tracked Since Feb 18, 2026