CVE-2005-2490
Summary
| CVE | CVE-2005-2490 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-09-14 19:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users to execute arbitrary code by calling sendmsg and modifying the message contents in another thread. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.0 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test10 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test11 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test5 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test6 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test7 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test8 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.0 | test9 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.1 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.1 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.10 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.11.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.12 | rc4 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.6 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.7 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8 | rc1 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8 | rc2 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.8 | rc3 | All | All |
| Operating System | Linux | Linux Kernel | 2.6.9 | 2.6.20 | All | All |
| Operating System | Linux | Linux Kernel | 2.6_test9_cvs | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Secunia - Advisories - Linux Kernel Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Debian update for kernel-source-2.6.8 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1017-1 kernel-source-2.6.8 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 166248 – CAN-2005-2490 sendmsg compat stack overflow | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Secunia - Advisories - Mandriva update for kernel | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| usn/usn-178-1 - Ubuntu Linux | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - Red Hat update for kernel | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1 | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Secunia - Advisories - SUSE update for kernel | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Secunia - Advisories - Red Hat update for kernel | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 'TSLSA-2005-0049 - multi' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Linux Kernel Sendmsg() Local Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.