PT-2003-1089 · Linux+1 · Linux+1
Published
2003-05-22
·
Updated
2017-10-11
·
CVE-2003-0461
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux kernel versions 2.4.20
Description
The issue affects the kernel package in Red Hat Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Additionally, a local user could obtain sensitive information, such as password lengths, by accessing the /proc/tty/driver/serial file in Linux 2.4.x.
Recommendations
For Red Hat Linux kernel version 2.4.20, consider updating to a newer version to mitigate the risk, although the specific fixed version is not provided. As a temporary workaround, restrict access to sensitive files and information to minimize the risk of exploitation. Avoid using potentially vulnerable kernel packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux
Red Hat