CVE-2003-0476

NameCVE-2003-0476
DescriptionThe execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-358, DSA-423
NVD severitylow (attack range: local)
Debian/oldoldstablenot known to be vulnerable.
Debian/oldstablenot known to be vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kernel-image-2.4.17-ia64sourcewoodykernel-image-2.4.17-ia64lowDSA-423
kernel-image-2.4.18-1-alphasourcewoody2.4.18-10.lowDSA-358
kernel-image-2.4.18-1-i386sourcewoody2.4.18-11lowDSA-358
kernel-image-2.4.18-i386bfsourcewoody2.4.18-5woody4lowDSA-358
kernel-source-2.4.18sourcewoody2.4.18-13lowDSA-358
kernel-source-2.4.27source(unstable)(not affected)

Notes

- kernel-source-2.4.27 <not-affected> (Fixed before upload in the archive; 2.4.22-pre4)

Search for package or bug name: Reporting problems