PT-2003-1065 · Red Hat · Red Hat+1
Johny Robertson
·
Published
2003-02-19
·
Updated
2008-09-11
·
CVE-2003-0019
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kernel-utils versions in Red Hat Linux 8.0
Description
The issue concerns incorrect setuid root privileges in the kernel-utils package, allowing local users to modify network interfaces. This can be done by modifying ARP entries or placing interfaces into promiscuous mode. Multiple vulnerabilities in the kernel-utils package may lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited locally.
Recommendations
For kernel-utils in Red Hat Linux 8.0, consider removing setuid root privileges from the uml net utility as a temporary workaround to prevent local users from modifying network interfaces until a patch is available. Restrict access to network interface modification tools to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Kernel-Utils