Executive Summary

Informations
Name CVE-2004-0114 First vendor Publication 2004-03-03
Vendor Cve Last vendor Modification 2017-10-10

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 4.6 Attack Range Local
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0114

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 126
Os 11
Os 10

OpenVAS Exploits

Date Description
2008-09-04 Name : FreeBSD Security Advisory (FreeBSD-SA-04:02.shmat.asc)
File : nvt/freebsdsa_shmat.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
3836 Multiple BSD shmat() Privilege Escalation

BSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when two separate mappings are created with shmat(2) to a shared memory segment created with shmget(2). If shmat(2) is abused and then one of the mappings delected with shmdt(2) the vm_object will continue to map to the shared memory segment. An suid binary may reuse the vm_object and allow the (non-root) user to write directly to the stack segment of the suid binary. This flaw may lead to a loss of integrity of the system.

Nessus® Vulnerability Scanner

Date Description
2004-07-06 Name : The remote device is missing a vendor-supplied security patch
File : freebsd_shmat.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/9586
BUGTRAQ http://marc.info/?l=bugtraq&m=107608375207601&w=2
CONFIRM http://www.openbsd.org/errata33.html#sysvshm
FREEBSD ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc
MISC http://www.pine.nl/press/pine-cert-20040201.txt
NETBSD ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc
OSVDB http://www.osvdb.org/3836
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/15061

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
Date Informations
2024-02-02 01:02:30
  • Multiple Updates
2024-02-01 12:01:30
  • Multiple Updates
2023-09-05 12:02:23
  • Multiple Updates
2023-09-05 01:01:22
  • Multiple Updates
2023-09-02 12:02:24
  • Multiple Updates
2023-09-02 01:01:22
  • Multiple Updates
2023-08-12 12:02:55
  • Multiple Updates
2023-08-12 01:01:22
  • Multiple Updates
2023-08-11 12:02:30
  • Multiple Updates
2023-08-11 01:01:23
  • Multiple Updates
2023-08-06 12:02:19
  • Multiple Updates
2023-08-06 01:01:23
  • Multiple Updates
2023-08-04 12:02:23
  • Multiple Updates
2023-08-04 01:01:23
  • Multiple Updates
2023-07-14 12:02:21
  • Multiple Updates
2023-07-14 01:01:23
  • Multiple Updates
2023-03-29 01:02:23
  • Multiple Updates
2023-03-28 12:01:28
  • Multiple Updates
2022-12-15 01:02:07
  • Multiple Updates
2022-10-11 12:02:06
  • Multiple Updates
2022-10-11 01:01:16
  • Multiple Updates
2021-05-05 01:01:34
  • Multiple Updates
2021-05-04 12:02:16
  • Multiple Updates
2021-04-22 01:02:25
  • Multiple Updates
2020-05-23 01:36:00
  • Multiple Updates
2020-05-23 00:15:43
  • Multiple Updates
2019-03-23 12:00:47
  • Multiple Updates
2019-03-20 12:01:26
  • Multiple Updates
2019-03-19 12:01:40
  • Multiple Updates
2017-10-10 09:23:26
  • Multiple Updates
2017-03-30 12:00:52
  • Multiple Updates
2016-10-18 12:01:17
  • Multiple Updates
2016-06-28 15:04:56
  • Multiple Updates
2016-04-26 12:46:54
  • Multiple Updates
2014-02-17 10:27:10
  • Multiple Updates
2013-05-11 11:39:53
  • Multiple Updates