CVE-2005-0400: Low severity Linux Linux kernel vulnerability
Published Apr 5, 2005
·Updated
The ext2makeempty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.
Affected Software
1 affected component
Linux Linux kernel<=2.6.11.6
Event History
Apr 5, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0400?
CVE-2005-0400 is classified as a medium severity vulnerability due to the potential for local users to access sensitive information.
2
Who is affected by CVE-2005-0400?
CVE-2005-0400 affects local users running Linux kernel versions prior to 2.6.11.6.
3
How do I fix CVE-2005-0400?
To mitigate CVE-2005-0400, update your Linux kernel to version 2.6.11.6 or later.
4
What type of exposure does CVE-2005-0400 present?
CVE-2005-0400 allows local users to read memory blocks, potentially exposing sensitive information.
5
Can CVE-2005-0400 be exploited remotely?
No, CVE-2005-0400 is a local vulnerability and cannot be exploited remotely.