MEDIUM · 5.0

CVE-2003-0001

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using mal...

Vulnerability Description

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
FreebsdFreebsd4.2
LinuxLinux Kernel2.4.1
MicrosoftWindows 2000All versions
MicrosoftWindows 2000 Terminal ServicesAll versions
NetbsdNetbsd1.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2003-0001?

CVE-2003-0001 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using mal...

How severe is CVE-2003-0001?

CVE-2003-0001 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0001?

Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd, Linux Linux Kernel, Microsoft Windows 2000, Microsoft Windows 2000 Terminal Services, Netbsd Netbsd.