PT-2003-1089 · Linux+1 · Linux+1

Published

2003-05-22

·

Updated

2017-10-11

·

CVE-2003-0461

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Linux kernel versions 2.4.20
Description The issue affects the kernel package in Red Hat Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Additionally, a local user could obtain sensitive information, such as password lengths, by accessing the /proc/tty/driver/serial file in Linux 2.4.x.
Recommendations For Red Hat Linux kernel version 2.4.20, consider updating to a newer version to mitigate the risk, although the specific fixed version is not provided. As a temporary workaround, restrict access to sensitive files and information to minimize the risk of exploitation. Avoid using potentially vulnerable kernel packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
CVE-2003-0461
DSA-358
DSA-423
RHSA-2004:188

Affected Products

Linux
Red Hat