Embedded malicious code in Linux kernel - CVE-2003-1161

 

Embedded malicious code in Linux kernel - CVE-2003-1161

Published: December 31, 2003 / Updated: September 5, 2008


Vulnerability identifier: #VU95660
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2003-1161
CWE-ID: CWE-506
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to execute arbitrary code.

exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.


How to mitigate CVE-2003-1161

Install update from vendor's repository.

Sources