CVE-2005-4605 describes a kernel memory disclosure vulnerability in the procfs code (proc_misc.c) of Linux kernel versions prior to 2.6.15, including 2.6.14.3. This flaw allows local attackers to read sensitive kernel memory due to an unspecified error involving signed and unsigned value addition. The vulnerability has a low CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating it requires local access and has a low attack complexity, primarily impacting confidentiality by disclosing kernel memory. There is no impact on integrity or availability. While not listed in CISA's KEV catalog and showing no active exploitation or significant community discussion, an exploit (EDB-9363) for kernel memory disclosure exists on ExploitDB. No Metasploit or Nuclei modules are available for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:* | ||
2.6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:* | ||
2.6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:* | ||
2.6.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:* | ||
2.6.14.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.