CVE-2004-2372
EPSS 0.70%
Description
Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.
How to fix CVE-2004-2372
To remediate CVE-2004-2372, upgrade the affected package to a fixed version below.
- Debian/bochs—upgrade to 2.1.1-1 or later
Is CVE-2004-2372 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.1-1