[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-0018Date: (C)2003-02-19   (M)2023-12-22


Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: PARTIAL
  
Reference:
BID-6763
DSA-358
DSA-423
MDKSA-2003:014
RHSA-2003:025
http://linux.bkbits.net:8080/linux-2.4/cset%403e2f193drGJDBg9SG6JwaDQwCBnAMQ
linux-odirect-information-leak(11249)

CPE    10
cpe:/o:linux:linux_kernel:2.4.15
cpe:/o:linux:linux_kernel:2.4.16
cpe:/o:linux:linux_kernel:2.4.13
cpe:/o:linux:linux_kernel:2.4.14
...

© SecPod Technologies