PT-2001-1018 · Linux+1 · Filesystem+7

Published

2001-10-09

·

Updated

2016-10-18

·

CVE-2001-1384

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.2.x through 2.2.19 Linux kernel versions 2.4.x through 2.4.9 e2fsprogs version 1.23 e2fsprogs-devel version 1.23 modutils version 2.4.6 initscripts version 5.84.1 filesystem version 2.1.0 mkinitrd version 3.2.6 krb5-libs version 1.2.2
Description The issue is related to multiple vulnerabilities in the Linux kernel and other packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done locally or remotely. The ptrace component in Linux is also affected by errors in the code, allowing a local attacker to elevate their privileges to the root user level by combining system calls exec and ptrace.
Recommendations For Linux kernel versions 2.2.x through 2.2.19, update to a newer version to mitigate the risk. For Linux kernel versions 2.4.x through 2.4.9, update to a newer version to mitigate the risk. For e2fsprogs version 1.23, update to a newer version to mitigate the risk. For e2fsprogs-devel version 1.23, update to a newer version to mitigate the risk. For modutils version 2.4.6, update to a newer version to mitigate the risk. For initscripts version 5.84.1, update to a newer version to mitigate the risk. For filesystem version 2.1.0, update to a newer version to mitigate the risk. For mkinitrd version 3.2.6, update to a newer version to mitigate the risk. For krb5-libs version 1.2.2, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the ptrace component until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07791
BDU:2015-07792
BDU:2015-07797
BDU:2015-07800
BDU:2015-07812
BDU:2015-07814
BDU:2015-08107
BDU:2015-08109
BDU:2015-08111
BDU:2015-08113
BDU:2015-08115
BDU:2015-08117
BDU:2015-08118
BDU:2015-08119
BDU:2015-08120
BDU:2015-08121
BDU:2015-08122
BDU:2015-08123
BDU:2015-08124
BDU:2015-08125
BDU:2015-08127
BDU:2015-08128
BDU:2015-08131
BDU:2015-08140
BDU:2016-02218
CVE-2001-1384

Affected Products

Linux Kernel
E2Fsprogs
E2Fsprogs-Devel
Filesystem
Initscripts
Krb5-Libs
Mkinitrd
Modutils