Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-0019Redhat Linux vulnerability

6 documents6 sources
Severity
7.2HIGHNVD
EPSS
0.7%
top 28.73%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 19
Latest updateApr 29

Description

uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDredhat/linux8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j663-gv7p-7947: uml_net in the kernel-utils package for Red Hat Linux 82022-04-29
CVEList
CVE-2003-0019: uml_net in the kernel-utils package for Red Hat Linux 82004-09-01

💥Exploits & PoCs

1
Exploit-DB
UML_NET - Integer Mismanagement Code Execution2003-05-23

📋Vendor Advisories

1
Red Hat
security flaw2003-02-07

💬Community

1
Bugzilla
CVE-2003-0019 security flaw2018-08-16
CVE-2003-0019 — Redhat Linux vulnerability | cvebase