SB2003061603 - Improper access control in Linux kernel
Published: June 16, 2003
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2003-0246)
The vulnerability allows a local user to read and manipulate data.
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.
Remediation
Install update from vendor's website.
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html
- http://marc.info/?l=bugtraq&m=105301461726555&w=2
- http://www.debian.org/security/2003/dsa-311
- http://www.debian.org/security/2003/dsa-312
- http://www.debian.org/security/2003/dsa-332
- http://www.debian.org/security/2003/dsa-336
- http://www.debian.org/security/2004/dsa-442
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:066
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
- http://www.redhat.com/support/errata/RHSA-2003-147.html
- http://www.redhat.com/support/errata/RHSA-2003-172.html
- http://www.turbolinux.com/security/TLSA-2003-41.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A278