First published: Fri Jul 25 2003(Updated: )
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Linux | =7.2 | |
Red Hat Linux | =8.0 | |
Red Hat Linux | =7.3 | |
Red Hat Linux | =9.0 | |
Red Hat Linux | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0461 is considered to have a moderate severity level as it can expose sensitive information to local users.
To fix CVE-2003-0461, upgrade to a patched version of the affected Red Hat Linux systems or apply the recommended security updates.
CVE-2003-0461 affects Red Hat Linux versions 7.1, 7.2, 7.3, 8.0, and 9.0.
CVE-2003-0461 can be exploited by local users with access to the system.
CVE-2003-0461 reveals the exact number of characters used in serial links, which may include sensitive information like password lengths.