PT-2003-1064 · Linux · Linux Kernel

Publicado

2003-02-19

·

Atualizado

2008-09-11

·

CVE-2003-0018

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.10 through 2.4.21-pre4
Description The issue affects the Linux kernel, allowing local attackers with write privileges to read portions of previously deleted files or cause file system corruption due to improper handling of the O DIRECT feature. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out locally.
Recommendations For Linux kernel versions 2.4.10 through 2.4.21-pre4, consider updating to a version that properly handles the O DIRECT feature to prevent file system corruption and unauthorized access to deleted files. As a temporary workaround, restrict local write privileges to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07934
BDU:2015-07935
BDU:2015-07938
BDU:2015-07939
BDU:2015-07942
BDU:2015-07953
BDU:2015-07956
CVE-2003-0018
DSA-358
DSA-423

Produtos afetados

Linux Kernel