PT-2003-1089 · Linux+1 · Linux+1
Publicado
2003-05-22
·
Atualizado
2017-10-11
·
CVE-2003-0461
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux kernel versions 2.4.20
Description
The issue affects the kernel package in Red Hat Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Additionally, a local user could obtain sensitive information, such as password lengths, by accessing the /proc/tty/driver/serial file in Linux 2.4.x.
Recommendations
For Red Hat Linux kernel version 2.4.20, consider updating to a newer version to mitigate the risk, although the specific fixed version is not provided. As a temporary workaround, restrict access to sensitive files and information to minimize the risk of exploitation. Avoid using potentially vulnerable kernel packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux
Red Hat