PT-2003-1102 · Red Hat+1 · Red Hat+1
Published
2003-05-22
·
Updated
2017-10-10
·
CVE-2004-0075
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.4.25
Red Hat Linux kernel-2.4.20 version
Red Hat Linux kernel-smp-2.4.20 version
Red Hat Linux kernel-doc-2.4.20 version
Red Hat Linux kernel-source-2.4.20 version
Red Hat Linux kernel-BOOT-2.4.20 version
Red Hat Linux kernel-bigmem-2.4.20 version
Description
The issue affects the Linux kernel and Red Hat Linux, allowing for potential disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. A specific problem is noted in the Vicam USB driver, which fails to use the copy from user function when copying data from userspace to kernel space, allowing local users to cause a denial of service.
Recommendations
For Linux kernel version prior to 2.4.25, update to version 2.4.25 or later.
For Red Hat Linux kernel-2.4.20 version, consider upgrading to a newer version.
For Red Hat Linux kernel-smp-2.4.20 version, consider upgrading to a newer version.
For Red Hat Linux kernel-doc-2.4.20 version, consider upgrading to a newer version.
For Red Hat Linux kernel-source-2.4.20 version, consider upgrading to a newer version.
For Red Hat Linux kernel-BOOT-2.4.20 version, consider upgrading to a newer version.
For Red Hat Linux kernel-bigmem-2.4.20 version, consider upgrading to a newer version.
As a temporary workaround, consider restricting access to the Vicam USB driver until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat