← Back

CVE-2004-2372

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.

Affected (1)

Products: Bochs Project: Bochs
1 product
Bochs
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.1.1

References (8)

Source: cve@mitre.org
PatchThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB Entry

Timeline

No history available yet.