PT-2003-1101 · Red Hat+1 · Red Hat+1
Published
2003-05-22
·
Updated
2018-08-13
·
CVE-2003-1040
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Linux kernel versions 2.4.20
Description
The issue affects the kernel package in Red Hat Linux, allowing for potential remote exploitation that could compromise confidentiality, integrity, and availability of protected information. Local users can also cause a denial of service by sending certain signals to kmod, as it does not set its uid, suid, gid, or sgid to 0.
Recommendations
For Red Hat Linux kernel version 2.4.20, consider updating to a newer version that contains a fix for this issue, as the current version is affected by multiple vulnerabilities that can be exploited remotely. Additionally, as a temporary workaround, consider restricting access to the kmod module to minimize the risk of local denial-of-service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat