SB2003080702 - Information exposure in Linux kernel



SB2003080702 - Information exposure in Linux kernel

Published: August 7, 2003

Security Bulletin ID SB2003080702
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information exposure (CVE-ID: CVE-2003-0476)

The vulnerability allows a local user to gain access to sensitive information.

The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.


Remediation

Install update from vendor's website.