PT-2002-3161 · Debian+2 · Mkcramfs+9

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2003-0246

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux (affected versions not specified) Red Hat Linux kernel versions prior to 2.4.21 Red Hat Linux kernel-smp version 2.4.20 Red Hat Linux kernel-doc version 2.4.20 Red Hat Linux kernel version 2.4.20 Red Hat Linux kernel-BOOT version 2.4.20 Red Hat Linux kernel-source version 2.4.20 Red Hat Linux kernel-bigmem version 2.4.20 Red Hat Linux oprofile version 0.4 Debian GNU/Linux pcmcia-modules version 2.4.18-bf2.4 Debian GNU/Linux mkcramfs (affected versions not specified)
Description The issue involves multiple vulnerabilities in various Linux kernel packages and related software, which can lead to disruptions in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to Mitre, the ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, allowing local users to gain read or write access to certain I/O ports.
Recommendations For Debian GNU/Linux, update the pcmcia-modules and mkcramfs packages to versions that are not affected by the vulnerabilities. For Red Hat Linux kernel-smp version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux kernel-doc version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux kernel version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux kernel-BOOT version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux kernel-source version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux kernel-bigmem version 2.4.20, update to a version that is not affected by the vulnerabilities. For Red Hat Linux oprofile version 0.4, update to a version that is not affected by the vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable kernel packages until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02820
BDU:2015-03498
BDU:2015-07979
BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
CVE-2003-0246
DSA-311
DSA-312
DSA-332
DSA-336
DSA-442

Affected Products

Debian
Linux Kernel
Linux Kernel-Boot
Linux Kernel-Bigmem
Linux Kernel-Doc
Linux Kernel-Smp
Linux Kernel-Source
Mkcramfs
Oprofile
Pcmcia-Modules