N-044Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/n-044.shtml CVE-2003-0019
UML_NET - Integer Mismanagement Code Execution
Record summary
CVE-2003-0019 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBUML_NET - Integer Mismanagement Code ExecutionExploitDB exploitby ktha@hushmail.comNot analyzed1 file
References
6linux-umlnet-gain-privileges(11276)vdb entry
http://www.iss.net/security_center/static/11276.php VU#134025Third-party advisory
http://www.kb.cert.org/vuls/id/134025 RHSA-2003:056Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-056.html 6801vdb entry
http://www.securityfocus.com/bid/6801 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0019