PT-2003-1065 · Red Hat · Red Hat+1
Johny Robertson
·
Publicado
2003-02-19
·
Atualizado
2008-09-11
·
CVE-2003-0019
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kernel-utils versions in Red Hat Linux 8.0
Description
The issue concerns incorrect setuid root privileges in the kernel-utils package, allowing local users to modify network interfaces. This can be done by modifying ARP entries or placing interfaces into promiscuous mode. Multiple vulnerabilities in the kernel-utils package may lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited locally.
Recommendations
For kernel-utils in Red Hat Linux 8.0, consider removing setuid root privileges from the uml net utility as a temporary workaround to prevent local users from modifying network interfaces until a patch is available. Restrict access to network interface modification tools to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Kernel-Utils