CVE-2005-0736: Integer Overflow
Published Mar 9, 2005
·Updated
Integer overflow in sysepollwait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.
Affected Software
19 affected components
Conectiva Linux=10.0
Linux Linux kernel=2.6.0
Linux Linux kernel=2.6.1
Linux Linux kernel=2.6.2
Linux Linux kernel=2.6.3
Linux Linux kernel=2.6.4
Linux Linux kernel=2.6.5
Linux Linux kernel=2.6.6
Linux Linux kernel=2.6.7
Linux Linux kernel=2.6.8
Linux Linux kernel=2.6.9-2.6.20
Linux Linux kernel=2.6.10
Linux Linux kernel=2.6.11
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=4.0
redhat Fedora Core=core_2.0
redhat Fedora Core=core_3.0
Remediation
Patch Available
Event History
Mar 9, 2005
CVE Published
05:00 AM
Mar 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0736?
CVE-2005-0736 is rated as a high severity vulnerability due to its potential to allow local users to overwrite kernel memory.
2
How do I fix CVE-2005-0736?
To fix CVE-2005-0736, you should upgrade your Linux kernel to a version that addresses this integer overflow vulnerability.
3
Which versions of the Linux kernel are affected by CVE-2005-0736?
CVE-2005-0736 affects Linux kernel versions from 2.6.0 to 2.6.11 inclusive.
4
What types of systems are impacted by CVE-2005-0736?
CVE-2005-0736 impacts various systems running affected versions of the Linux kernel including Conectiva Linux and Red Hat Enterprise Linux.
5
Can CVE-2005-0736 be exploited remotely?
CVE-2005-0736 is primarily a local vulnerability, meaning it requires local access to the system to be exploited.