SB2003123104 - Embedded malicious code in Linux kernel
Published: December 31, 2003
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Embedded malicious code (CVE-ID: CVE-2003-1161)
The vulnerability allows a local user to execute arbitrary code.
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.
Remediation
Install update from vendor's website.