VulnerabilityModified
CVE-2005-0504
Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
MEDIUM 4.6EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- linux/linux kernel
- Source
- security@debian.org
References
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html
- http://secunia.com/advisories/17002Vendor Advisory
- http://secunia.com/advisories/20163Vendor Advisory
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338Vendor Advisory
- http://secunia.com/advisories/26651Vendor Advisory
- http://secunia.com/advisories/30112
- http://securitytracker.com/id?1013273
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
- http://www.debian.org/security/2006/dsa-1070
- http://www.debian.org/security/2006/dsa-1082
- http://www.redhat.com/support/errata/RHSA-2005-529.html
- http://www.redhat.com/support/errata/RHSA-2005-551.html
- http://www.redhat.com/support/errata/RHSA-2005-663.html
- http://www.redhat.com/support/errata/RHSA-2008-0237.html
- http://www.securityfocus.com/bid/12195Patch, Vendor Advisory
- http://www.ubuntu.com/usn/usn-508-1
- http://www.vupen.com/english/advisories/2005/1878
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9770
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html
- http://secunia.com/advisories/17002Vendor Advisory
- http://secunia.com/advisories/20163Vendor Advisory
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338Vendor Advisory
- http://secunia.com/advisories/26651Vendor Advisory
- http://secunia.com/advisories/30112
- http://securitytracker.com/id?1013273
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.