CVE-2004-0491: Low severity redhat Enterprise Linux vulnerability
Published Dec 31, 2004
·Updated
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
Affected Software
1 affected component
redhat Enterprise Linux=3.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0491?
CVE-2004-0491 is considered a moderate severity vulnerability that affects local memory management.
2
How do I fix CVE-2004-0491?
Fix CVE-2004-0491 by applying the appropriate security patch provided by Red Hat for Enterprise Linux 3.
3
Who is affected by CVE-2004-0491?
Local users of Red Hat Enterprise Linux 3 are affected by CVE-2004-0491 due to improper memory locking.
4
What are the potential consequences of exploiting CVE-2004-0491?
Exploiting CVE-2004-0491 can allow users to mlock more memory than allowed, potentially leading to denial of service.
5
Is CVE-2004-0491 specific to any version of Red Hat Enterprise Linux?
Yes, CVE-2004-0491 specifically affects Red Hat Enterprise Linux 3.0.