PT-2002-3160 · Linux · Kernel-Smp+8
Publicado
1970-01-01
·
Atualizado
2016-10-18
·
CVE-2002-0429
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4.18 and earlier
kernel-smp-2.4.18
kernel-source-2.4.18
kernel-2.4.18
kernel-BOOT-2.4.18
kernel-doc-2.4.18
kernel-debug-2.4.18
kernel-bigmem-2.4.18
pcmcia-modules-2.4.18-bf2.4
mkcramfs
Description
The issue affects the Linux kernel and various related packages, allowing for potential exploitation that could lead to breaches in confidentiality, integrity, and availability of protected information. Exploitation can be carried out both locally and remotely, depending on the specific vulnerability. The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a binary compatibility interface.
Recommendations
For Linux kernel versions 2.4.18 and earlier, consider upgrading to a newer version to mitigate the risk.
For kernel-smp-2.4.18, kernel-source-2.4.18, kernel-2.4.18, kernel-BOOT-2.4.18, kernel-doc-2.4.18, kernel-debug-2.4.18, and kernel-bigmem-2.4.18, restrict local access to minimize the risk of exploitation.
For pcmcia-modules-2.4.18-bf2.4 and mkcramfs, restrict remote access to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Kernel-Boot
Kernel-Bigmem
Kernel-Debug
Kernel-Doc
Kernel-Smp
Kernel-Source
Mkcramfs
Pcmcia-Modules