CVE-2003-0461 Information

Description

/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links which could allow local users to obtain potentially sensitive information such as the length of passwords.

Reference

http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html http://www.debian.org/security/2004/dsa-358 http://www.debian.org/security/2004/dsa-423 http://www.redhat.com/support/errata/RHSA-2003-238.html http://www.redhat.com/support/errata/RHSA-2004-188.html https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A304 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9330 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A997

Share on: