CVE-2003-0476

Linux Kernel 2.4.x - Unauthorized File Descriptor Access via execve System Call

Title source: llm
STIX 2.1

Description

The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A327
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105664924024009&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-238.html
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-423
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-408.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-358
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-368.html

Scores

EPSS 0.0041
EPSS Percentile 33.6%

Details

Status published
Products (1)
linux/linux_kernel 2.4.0
Published Aug 07, 2003
Tracked Since Feb 18, 2026