CVE-2004-2408: Low severity vserver Linux-VServer vulnerability
Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to set permissions in /proc to obtain system information or cause a denial of service on other virtual servers or the host server.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2408?
CVE-2004-2408 is classified as a high severity vulnerability that affects the security of Linux VServer configurations.
How do I fix CVE-2004-2408?
To fix CVE-2004-2408, upgrade to a patched version of Linux VServer beyond the affected versions.
What are the affected versions in CVE-2004-2408?
CVE-2004-2408 affects Linux VServer versions 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier.
What risk does CVE-2004-2408 pose to a system?
CVE-2004-2408 allows local users to obtain sensitive system information or create a denial of service on both virtual and host servers.
Who is vulnerable to CVE-2004-2408?
Local users with the ability to set permissions in /proc on vulnerable Linux VServer installations are at risk from CVE-2004-2408.