PT-2002-3160 · Linux · Kernel-Smp+8

Published

1970-01-01

·

Updated

2016-10-18

·

CVE-2002-0429

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.4.18 and earlier kernel-smp-2.4.18 kernel-source-2.4.18 kernel-2.4.18 kernel-BOOT-2.4.18 kernel-doc-2.4.18 kernel-debug-2.4.18 kernel-bigmem-2.4.18 pcmcia-modules-2.4.18-bf2.4 mkcramfs
Description The issue affects the Linux kernel and various related packages, allowing for potential exploitation that could lead to breaches in confidentiality, integrity, and availability of protected information. Exploitation can be carried out both locally and remotely, depending on the specific vulnerability. The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a binary compatibility interface.
Recommendations For Linux kernel versions 2.4.18 and earlier, consider upgrading to a newer version to mitigate the risk. For kernel-smp-2.4.18, kernel-source-2.4.18, kernel-2.4.18, kernel-BOOT-2.4.18, kernel-doc-2.4.18, kernel-debug-2.4.18, and kernel-bigmem-2.4.18, restrict local access to minimize the risk of exploitation. For pcmcia-modules-2.4.18-bf2.4 and mkcramfs, restrict remote access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02820
BDU:2015-03498
BDU:2015-07934
BDU:2015-07935
BDU:2015-07938
BDU:2015-07939
BDU:2015-07942
BDU:2015-07953
BDU:2015-07956
CVE-2002-0429
DSA-311
DSA-312
DSA-332
DSA-336
DSA-442

Affected Products

Linux Kernel
Kernel-Boot
Kernel-Bigmem
Kernel-Debug
Kernel-Doc
Kernel-Smp
Kernel-Source
Mkcramfs
Pcmcia-Modules