CVE-2003-0127

The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.
References
Link Resource
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html
http://marc.info/?l=bugtraq&m=105301461726555&w=2
http://rhn.redhat.com/errata/RHSA-2003-088.html
http://rhn.redhat.com/errata/RHSA-2003-098.html Patch Vendor Advisory
http://security.gentoo.org/glsa/glsa-200303-17.xml
http://www.debian.org/security/2003/dsa-270
http://www.debian.org/security/2003/dsa-276
http://www.debian.org/security/2003/dsa-311
http://www.debian.org/security/2003/dsa-312
http://www.debian.org/security/2003/dsa-332
http://www.debian.org/security/2003/dsa-336
http://www.debian.org/security/2004/dsa-423
http://www.debian.org/security/2004/dsa-495
http://www.kb.cert.org/vuls/id/628849 Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:038
http://www.mandriva.com/security/advisories?name=MDKSA-2003:039
http://www.redhat.com/support/errata/RHSA-2003-103.html
http://www.redhat.com/support/errata/RHSA-2003-145.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html
http://marc.info/?l=bugtraq&m=105301461726555&w=2
http://rhn.redhat.com/errata/RHSA-2003-088.html
http://rhn.redhat.com/errata/RHSA-2003-098.html Patch Vendor Advisory
http://security.gentoo.org/glsa/glsa-200303-17.xml
http://www.debian.org/security/2003/dsa-270
http://www.debian.org/security/2003/dsa-276
http://www.debian.org/security/2003/dsa-311
http://www.debian.org/security/2003/dsa-312
http://www.debian.org/security/2003/dsa-332
http://www.debian.org/security/2003/dsa-336
http://www.debian.org/security/2004/dsa-423
http://www.debian.org/security/2004/dsa-495
http://www.kb.cert.org/vuls/id/628849 Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:038
http://www.mandriva.com/security/advisories?name=MDKSA-2003:039
http://www.redhat.com/support/errata/RHSA-2003-103.html
http://www.redhat.com/support/errata/RHSA-2003-145.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:2.2.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.13:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.14:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.15:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.16:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.17:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.18:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.20:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.21:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.22:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.23:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.2.24:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.12:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.13:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.14:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.15:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.16:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.17:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.18:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.20:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.4.21:pre1:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt - () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt -
References () http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html - () http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html -
References () http://marc.info/?l=bugtraq&m=105301461726555&w=2 - () http://marc.info/?l=bugtraq&m=105301461726555&w=2 -
References () http://rhn.redhat.com/errata/RHSA-2003-088.html - () http://rhn.redhat.com/errata/RHSA-2003-088.html -
References () http://rhn.redhat.com/errata/RHSA-2003-098.html - Patch, Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2003-098.html - Patch, Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200303-17.xml - () http://security.gentoo.org/glsa/glsa-200303-17.xml -
References () http://www.debian.org/security/2003/dsa-270 - () http://www.debian.org/security/2003/dsa-270 -
References () http://www.debian.org/security/2003/dsa-276 - () http://www.debian.org/security/2003/dsa-276 -
References () http://www.debian.org/security/2003/dsa-311 - () http://www.debian.org/security/2003/dsa-311 -
References () http://www.debian.org/security/2003/dsa-312 - () http://www.debian.org/security/2003/dsa-312 -
References () http://www.debian.org/security/2003/dsa-332 - () http://www.debian.org/security/2003/dsa-332 -
References () http://www.debian.org/security/2003/dsa-336 - () http://www.debian.org/security/2003/dsa-336 -
References () http://www.debian.org/security/2004/dsa-423 - () http://www.debian.org/security/2004/dsa-423 -
References () http://www.debian.org/security/2004/dsa-495 - () http://www.debian.org/security/2004/dsa-495 -
References () http://www.kb.cert.org/vuls/id/628849 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/628849 - Third Party Advisory, US Government Resource
References () http://www.mandriva.com/security/advisories?name=MDKSA-2003:038 - () http://www.mandriva.com/security/advisories?name=MDKSA-2003:038 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2003:039 - () http://www.mandriva.com/security/advisories?name=MDKSA-2003:039 -
References () http://www.redhat.com/support/errata/RHSA-2003-103.html - () http://www.redhat.com/support/errata/RHSA-2003-103.html -
References () http://www.redhat.com/support/errata/RHSA-2003-145.html - () http://www.redhat.com/support/errata/RHSA-2003-145.html -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254 -

Information

Published : 2003-03-31 05:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0127

Mitre link : CVE-2003-0127

CVE.ORG link : CVE-2003-0127


JSON object : View

Products Affected

linux

  • linux_kernel