Back to Database
Status published
Low
CVE-2003-0462
A race condition in the way env_start and env_end pointers...
Vulnerability Description
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-0462
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2003-238.html
- http://www.debian.org/security/2004/dsa-423
- http://www.redhat.com/support/errata/RHSA-2003-198.html
- http://www.redhat.com/support/errata/RHSA-2003-239.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A309
- http://www.debian.org/security/2004/dsa-358
More from mandrakesoft
View All →CVE-2007-1352
Integer overflow in the FontFileInitTable function in X.Org libXfont before...
Low
3.8
CVE-2005-2377
nss_ldap 181 to versions before 213, as used in Mandrake...
Medium
5
CVE-2005-1379
The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs...
Medium
4.6
CVE-2004-2395
Memory leak in passwd 0.68 allows local users to cause...
Low
2.1
CVE-2004-2394
Off-by-one error in passwd 0.68 and earlier, when using the...
Low
2.1
Affected Vendor
mandrakesoft
View all reports →Affected Software
mandrake multi network firewall, linux kernel, mandrake linux, mandrake linux corporate server
Vulnerable Versions:
8.2, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 2.4.10, 2.4.11, 2.4.12, 2.4.13, 2.4.14, 2.4.15, 2.4.16, 2.4.17, 2.4.18, 2.4.19, 2.4.20, 2.4.21, 9.0, 2.1
Timeline
Official Publish:
July 25th, 2003
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.