CVE-2003-0461

NameCVE-2003-0461
Description/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-358, DSA-423

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kernel-image-2.4.17-ia64sourcewoodykernel-image-2.4.17-ia64DSA-423
kernel-image-2.4.18-1-alphasourcewoody2.4.18-10.DSA-358
kernel-image-2.4.18-1-i386sourcewoody2.4.18-11DSA-358
kernel-image-2.4.18-i386bfsourcewoody2.4.18-5woody4DSA-358
kernel-source-2.4.18sourcewoody2.4.18-13DSA-358
kernel-source-2.4.27source(unstable)2.4.27-1
kernel-source-2.6.8sourcesarge(not affected)
linux-2.6source(unstable)(not affected)

Notes

[sarge] - kernel-source-2.6.8 <not-affected> (Fixed before upload into archive; 2.6.1)
- linux-2.6 <not-affected> (Fixed before upload into archive; 2.6.1)

Search for package or bug name: Reporting problems