Vulnerabilities > CVE-2003-0464 - Local Security vulnerability in Linux

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
redhat

Summary

The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.

Vulnerable Configurations

Part Description Count
OS
Redhat
5

Oval

accepted2007-04-25T19:52:27.102-04:00
classvulnerability
contributors
  • nameJay Beale
    organizationBastille Linux
  • nameJay Beale
    organizationBastille Linux
  • nameThomas R. Jones
    organizationMaitreya Security
descriptionThe RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
familyunix
idoval:org.mitre.oval:def:311
statusaccepted
submitted2003-09-26T12:00:00.000-04:00
titleLinux Kernel Reuse Flag Vulnerability
version38

Redhat

advisories
rhsa
idRHSA-2003:238