PT-2003-1101 · Red Hat+1 · Red Hat+1

Published

2003-05-22

·

Updated

2018-08-13

·

CVE-2003-1040

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Linux kernel versions 2.4.20
Description The issue affects the kernel package in Red Hat Linux, allowing for potential remote exploitation that could compromise confidentiality, integrity, and availability of protected information. Local users can also cause a denial of service by sending certain signals to kmod, as it does not set its uid, suid, gid, or sgid to 0.
Recommendations For Red Hat Linux kernel version 2.4.20, consider updating to a newer version that contains a fix for this issue, as the current version is affected by multiple vulnerabilities that can be exploited remotely. Additionally, as a temporary workaround, consider restricting access to the kmod module to minimize the risk of local denial-of-service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08108
BDU:2015-08110
BDU:2015-08112
BDU:2015-08116
BDU:2015-08126
BDU:2015-08129
CVE-2003-1040
RHSA-2004:188

Affected Products

Linux Kernel
Red Hat