CVE-2003-0018: Low severity Linux Linux kernel vulnerability
Published Feb 19, 2003
·Updated
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the ODIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.
Affected Software
10 affected components
Linux Linux kernel=2.4.15
Linux Linux kernel=2.4.11
Linux Linux kernel=2.4.12
Linux Linux kernel=2.4.13
Linux Linux kernel=2.4.17
Linux Linux kernel=2.4.10
Linux Linux kernel=2.4.16
Linux Linux kernel=2.4.19
Linux Linux kernel=2.4.14
Linux Linux kernel=2.4.18
Remediation
Patch Available
Patch Available
Event History
Feb 19, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0018?
CVE-2003-0018 is classified as a medium severity vulnerability.
2
How do I fix CVE-2003-0018?
To fix CVE-2003-0018, upgrade your Linux kernel to version 2.4.22 or later.
3
What are the potential impacts of CVE-2003-0018?
The potential impacts of CVE-2003-0018 include unauthorized access to deleted files and possible file system corruption.
4
Which versions of Linux are affected by CVE-2003-0018?
CVE-2003-0018 affects Linux kernel versions 2.4.10 through 2.4.21-pre4.
5
Who can exploit CVE-2003-0018?
CVE-2003-0018 can be exploited by local attackers who have write privileges.