PT-2003-2533 · Red Hat+2 · Red Hat+2
Published
1970-01-01
·
Updated
2017-10-11
·
CVE-2003-0984
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.4.23 and earlier
Red Hat Linux kernel versions 2.4.20
Debian GNU/Linux kernel versions 2.4.18 and 2.4.19
Description
The issue affects the Linux kernel and can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely. The real-time clock (RTC) routines in the Linux kernel do not properly initialize their structures, which could leak kernel data to user space.
Recommendations
For Linux kernel versions 2.4.23 and earlier, update to a version later than 2.4.23.
For Red Hat Linux kernel versions 2.4.20, update to a version later than 2.4.20.
For Debian GNU/Linux kernel versions 2.4.18 and 2.4.19, update to a version later than 2.4.19.
As a temporary workaround, consider restricting access to the vulnerable kernel components until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Red Hat