CVE-2002-1963: Low severity Linux Linux kernel vulnerability
Published Dec 31, 2002
·Updated
Linux kernel 2.4.1 through 2.4.19 sets root's NRRESERVEDFILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries.
Affected Software
25 affected components
Linux Linux kernel=2.4.15
Linux Linux kernel=2.4.11
Linux Linux kernel=2.4.19-pre1
Linux Linux kernel=2.4.12
Linux Linux kernel=2.4.13
Linux Linux kernel=2.4.19-pre4
Linux Linux kernel=2.4.17
Linux Linux kernel=2.4.7
Linux Linux kernel=2.4.9
Linux Linux kernel=2.4.19-pre6
Linux Linux kernel=2.4.10
Linux Linux kernel=2.4.2
Linux Linux kernel=2.4.19-pre2
Linux Linux kernel=2.4.16
Linux Linux kernel=2.4.8
Linux Linux kernel=2.4.19-pre3
Linux Linux kernel=2.4.14
Linux Linux kernel=2.4.18
Linux Linux kernel=2.4.19-pre5
Linux Linux kernel=2.4.5
Linux Linux kernel=2.4.18
Linux Linux kernel=2.4.3
Linux Linux kernel=2.4.1
Linux Linux kernel=2.4.4
Linux Linux kernel=2.4.6
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1963?
CVE-2002-1963 has a severity rating of medium as it allows local users to cause resource exhaustion, potentially leading to a denial of service.
2
How do I fix CVE-2002-1963?
To fix CVE-2002-1963, you should upgrade the Linux kernel to a version higher than 2.4.19.
3
Who is affected by CVE-2002-1963?
CVE-2002-1963 affects users of Linux kernel versions 2.4.1 through 2.4.19.
4
What is the root cause of CVE-2002-1963?
The root cause of CVE-2002-1963 is the NR_RESERVED_FILES limit, which is set too low for the root user.
5
Can CVE-2002-1963 be exploited remotely?
No, CVE-2002-1963 can only be exploited locally by logged-in users.