Information exposure in Linux kernel - CVE-2003-0001
Published: January 17, 2003 / Updated: August 10, 2024
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
Affected software
How to mitigate CVE-2003-0001
Links to Public Exploits and PoC-codes
- Exploit #10372 - Cisco ASA < 8.4.4.6 < 8.2.5.32 - Ethernet Information Leak (August 10, 2024)
- Exploit #10355 - Ethernet Device Drivers Frame Padding - Info Leakage Exploit (Etherleak) (August 10, 2024)
- Exploit #10354 - Linux Kernel 2.0.x/2.2.x/2.4.x (FreeBSD 4.x) - Network Device Driver Frame Padding Information Disclosure (August 10, 2024)
External References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
- http://marc.info/?l=bugtraq&m=104222046632243&w=2
- http://secunia.com/advisories/7996
- http://www.atstake.com/research/advisories/2003/a010603-1.txt
- http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
- http://www.kb.cert.org/vuls/id/412115
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.osvdb.org/9962
- http://www.redhat.com/support/errata/RHSA-2003-025.html
- http://www.redhat.com/support/errata/RHSA-2003-088.html
- http://www.securityfocus.com/archive/1/305335/30/26420/threaded
- http://www.securityfocus.com/archive/1/307564/30/26270/threaded
- http://www.securitytracker.com/id/1031583
- http://www.securitytracker.com/id/1040185
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665