VulnerabilityModified
CVE-2004-1058
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
LOW 1.2EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
- CVSS 2.0
- 1.2 LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · ubuntu/ubuntu linux
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
- http://secunia.com/advisories/18684
- http://secunia.com/advisories/19038
- http://secunia.com/advisories/19369
- http://secunia.com/advisories/19607
- http://secunia.com/advisories/21476
- http://www.debian.org/security/2006/dsa-1018
- http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
- http://www.redhat.com/support/errata/RHSA-2005-293.html
- http://www.redhat.com/support/errata/RHSA-2006-0190.html
- http://www.redhat.com/support/errata/RHSA-2006-0191.html
- http://www.securityfocus.com/bid/11052
- http://www.securityfocus.com/bid/11937Patch, Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17151
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10427
- https://usn.ubuntu.com/38-1/
- ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
- http://secunia.com/advisories/18684
- http://secunia.com/advisories/19038
- http://secunia.com/advisories/19369
- http://secunia.com/advisories/19607
- http://secunia.com/advisories/21476
- http://www.debian.org/security/2006/dsa-1018
- http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:022
- http://www.redhat.com/support/errata/RHSA-2005-293.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.