CVE-2003-0476: Low severity Linux Linux kernel vulnerability
Published Jun 28, 2003
·Updated
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.
Affected Software
1 affected component
Linux Linux kernel=2.4.0
Remediation
Patch Available
Patch Available
Event History
Jun 28, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 7, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0476?
CVE-2003-0476 has a severity rating of moderate, as it allows local users to access restricted file descriptors.
2
How do I fix CVE-2003-0476?
To fix CVE-2003-0476, you should upgrade your Linux kernel to a version later than 2.4.0.
3
What systems are affected by CVE-2003-0476?
CVE-2003-0476 affects Linux kernel version 2.4.0.
4
Can CVE-2003-0476 be exploited remotely?
CVE-2003-0476 cannot be exploited remotely; it requires local access to the system.
5
What kind of access does CVE-2003-0476 provide to an attacker?
CVE-2003-0476 provides local users with unnecessary read access to restricted file descriptors.