CVE-2004-0535: Buffer Overflow
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0535?
CVE-2004-0535 is classified as a medium severity vulnerability due to the potential for local users to read sensitive kernel memory.
How do I fix CVE-2004-0535?
To fix CVE-2004-0535, upgrade to a later version of the Linux kernel that properly initializes memory.
What systems are affected by CVE-2004-0535?
CVE-2004-0535 affects Linux kernel versions 2.4.26 and earlier, particularly in distributions like Conectiva Linux, SUSE Linux, and Mandrake Linux.
Can CVE-2004-0535 be exploited remotely?
CVE-2004-0535 cannot be exploited remotely as it requires local access to the vulnerable system.
What is the nature of the issue in CVE-2004-0535?
CVE-2004-0535 is due to the e1000 driver not properly initializing memory, allowing local users to access portions of kernel memory.