SB2003011701 - Information exposure in Linux kernel



SB2003011701 - Information exposure in Linux kernel

Published: January 17, 2003 Updated: August 10, 2024

Security Bulletin ID SB2003011701
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information exposure (CVE-ID: CVE-2003-0001)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.


Remediation

Install update from vendor's website.