CVE-2005-1589
Summary
| CVE | CVE-2005-1589 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-17 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | rc4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| '[PATCH] Fix root hole in pktcdvd' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Neohapsis Archives - VulnWatch - #0045 - [VulnWatch] Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Patch, Vendor Advisory |
| Secunia - Advisories - Mandriva update for kernel | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Multiple Linux Kernel IOCTL Handlers Local Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Neohapsis Archives - VulnWatch - #0047 - [VulnWatch] Linux kernel pktcdvd ioctl break user space limit vulnerability [corrected] | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Neohapsis Archives - VulnWatch - #0046 - Re: [VulnWatch] Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10 | af854a3a-2127-422b-91ae-364da2661108 | kernel.org | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.