SB2004060103 - Information exposure in Linux kernel



SB2004060103 - Information exposure in Linux kernel

Published: June 1, 2004

Security Bulletin ID SB2004060103
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information exposure (CVE-ID: CVE-2004-0177)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.


Remediation

Install update from vendor's website.