Executive Summary

Informations
Name CVE-2003-0246 First vendor Publication 2003-06-16
Vendor Cve Last vendor Modification 2017-10-11

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:N)
Cvss Base Score 3.6 Attack Range Local
Cvss Impact Score 4.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0246

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:278
 
Oval ID: oval:org.mitre.oval:def:278
Title: Linux ioperm Privilege Restriction Vulnerability
Description: The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.
Family: unix Class: vulnerability
Reference(s): CVE-2003-0246
Version: 2
Platform(s): Red Hat Linux 9
Product(s): Linux kernel
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 91

OpenVAS Exploits

Date Description
2008-01-17 Name : Debian Security Advisory DSA 311-1 (kernel)
File : nvt/deb_311_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 312-1 (kernel-patch-2.4.18-powerpc)
File : nvt/deb_312_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 332-1 (kernel-source-2.4.17, kernel-patch-2.4.17...
File : nvt/deb_332_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 336-1 (kernel-source-2.2.20, kernel-image-2.2.20...
File : nvt/deb_336_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 442-1 (kernel-patch-2.4.17-s390, kernel-image-2....
File : nvt/deb_442_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
4454 Linux Kernel ioperm System Call Arbitrary Port read/write Access

Nessus® Vulnerability Scanner

Date Description
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-311.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-312.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-332.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-336.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-442.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2003-066.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2003-074.nasl - Type : ACT_GATHER_INFO
2004-07-06 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2003-147.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
DEBIAN http://www.debian.org/security/2003/dsa-311
http://www.debian.org/security/2003/dsa-312
http://www.debian.org/security/2003/dsa-332
http://www.debian.org/security/2003/dsa-336
http://www.debian.org/security/2004/dsa-442
ENGARDE http://marc.info/?l=bugtraq&m=105301461726555&w=2
MANDRAKE http://www.mandriva.com/security/advisories?name=MDKSA-2003:066
http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
REDHAT http://www.redhat.com/support/errata/RHSA-2003-147.html
http://www.redhat.com/support/errata/RHSA-2003-172.html
TURBO http://www.turbolinux.com/security/TLSA-2003-41.txt
VULNWATCH http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
Date Informations
2024-02-02 01:02:14
  • Multiple Updates
2024-02-01 12:01:26
  • Multiple Updates
2023-09-05 12:02:08
  • Multiple Updates
2023-09-05 01:01:18
  • Multiple Updates
2023-09-02 12:02:09
  • Multiple Updates
2023-09-02 01:01:17
  • Multiple Updates
2023-08-12 12:02:38
  • Multiple Updates
2023-08-12 01:01:18
  • Multiple Updates
2023-08-11 12:02:14
  • Multiple Updates
2023-08-11 01:01:19
  • Multiple Updates
2023-08-06 12:02:04
  • Multiple Updates
2023-08-06 01:01:19
  • Multiple Updates
2023-08-04 12:02:08
  • Multiple Updates
2023-08-04 01:01:19
  • Multiple Updates
2023-07-14 12:02:06
  • Multiple Updates
2023-07-14 01:01:19
  • Multiple Updates
2023-03-29 01:02:05
  • Multiple Updates
2023-03-28 12:01:24
  • Multiple Updates
2022-10-11 12:01:52
  • Multiple Updates
2022-10-11 01:01:11
  • Multiple Updates
2021-05-04 12:02:01
  • Multiple Updates
2021-04-22 01:02:08
  • Multiple Updates
2020-05-23 00:15:23
  • Multiple Updates
2017-10-11 09:23:16
  • Multiple Updates
2016-10-18 12:01:10
  • Multiple Updates
2016-04-26 12:31:32
  • Multiple Updates
2014-02-17 10:26:01
  • Multiple Updates
2013-05-11 11:50:56
  • Multiple Updates