PT-2003-1101 · Red Hat+1 · Red Hat+1

Publicado

2003-05-22

·

Atualizado

2018-08-13

·

CVE-2003-1040

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Linux kernel versions 2.4.20
Description The issue affects the kernel package in Red Hat Linux, allowing for potential remote exploitation that could compromise confidentiality, integrity, and availability of protected information. Local users can also cause a denial of service by sending certain signals to kmod, as it does not set its uid, suid, gid, or sgid to 0.
Recommendations For Red Hat Linux kernel version 2.4.20, consider updating to a newer version that contains a fix for this issue, as the current version is affected by multiple vulnerabilities that can be exploited remotely. Additionally, as a temporary workaround, consider restricting access to the kmod module to minimize the risk of local denial-of-service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
CVE-2003-1040
RHSA-2004:188

Produtos afetados

Linux Kernel
Red Hat