CVE-2003-0985
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.2%
from disclosure to weapon0 days
Published on NVDSep 1
1st PoCJan 6
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/145exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/141exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/142⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://patches.sgi.com/support/free/security/advisories/20040102-01-Uhttp://archives.neohapsis.com/archives/bugtraq/2004-01/0070.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000799http://download.immunix.org/ImmunixOS/7.3/updates/IMNX-2004-73-001-01http://isec.pl/vulnerabilities/isec-0013-mremap.txthttp://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremaphttp://marc.info/?l=bugtraq&m=107332754521495&w=2http://marc.info/?l=bugtraq&m=107332782121916&w=2http://marc.info/?l=bugtraq&m=107340358402129&w=2http://marc.info/?l=bugtraq&m=107340814409017&w=2http://marc.info/?l=bugtraq&m=107350348418373&w=2http://marc.info/?l=bugtraq&m=107394143105081&w=2