VulnerabilityModified
CVE-2003-0246
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.
LOW 3.6EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html
- http://marc.info/?l=bugtraq&m=105301461726555&w=2
- http://www.debian.org/security/2003/dsa-311Patch, Vendor Advisory
- http://www.debian.org/security/2003/dsa-312
- http://www.debian.org/security/2003/dsa-332
- http://www.debian.org/security/2003/dsa-336
- http://www.debian.org/security/2004/dsa-442
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:066
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
- http://www.redhat.com/support/errata/RHSA-2003-147.html
- http://www.redhat.com/support/errata/RHSA-2003-172.htmlPatch, Vendor Advisory
- http://www.turbolinux.com/security/TLSA-2003-41.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A278
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html
- http://marc.info/?l=bugtraq&m=105301461726555&w=2
- http://www.debian.org/security/2003/dsa-311Patch, Vendor Advisory
- http://www.debian.org/security/2003/dsa-312
- http://www.debian.org/security/2003/dsa-332
- http://www.debian.org/security/2003/dsa-336
- http://www.debian.org/security/2004/dsa-442
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:066
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
- http://www.redhat.com/support/errata/RHSA-2003-147.html
- http://www.redhat.com/support/errata/RHSA-2003-172.htmlPatch, Vendor Advisory
- http://www.turbolinux.com/security/TLSA-2003-41.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A278
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.