PT-2003-1100 · Red Hat+1 · Red Hat+1

Trini

·

Published

2003-05-22

·

Updated

2018-05-03

·

CVE-2003-0985

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.4.21 Red Hat Linux kernel-2.4.20 Red Hat Linux kernel-smp-2.4.20 Red Hat Linux kernel-doc-2.4.20 Red Hat Linux kernel-source-2.4.20 Red Hat Linux kernel-BOOT-2.4.20 Red Hat Linux kernel-bigmem-2.4.20
Description The issue concerns multiple vulnerabilities in the Linux kernel, specifically affecting Red Hat Linux, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability in the mremap system call (do mremap) in Linux kernel versions before 2.4.21 allows local users to cause a denial of service and possibly gain privileges by creating a zero-length virtual memory area (VMA).
Recommendations For Linux kernel versions prior to 2.4.21, update to version 2.4.21 or later. For Red Hat Linux kernel-2.4.20, consider disabling vulnerable functions until a patch is available. For Red Hat Linux kernel-smp-2.4.20, kernel-doc-2.4.20, kernel-source-2.4.20, kernel-BOOT-2.4.20, and kernel-bigmem-2.4.20, restrict access to vulnerable components to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the mremap system call (do mremap) until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
CVE-2003-0985
DSA-413
DSA-417
DSA-423
DSA-427
DSA-439
DSA-440
DSA-442
DSA-450
DSA-470
DSA-475
RHSA-2003:416

Affected Products

Linux Kernel
Red Hat