Vulnerability Description
Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.4.0 |
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000799
- http://marc.info/?l=bugtraq&m=107394143105081&w=2
- http://secunia.com/advisories/10533
- http://secunia.com/advisories/10536
- http://secunia.com/advisories/10537
- http://secunia.com/advisories/10538
- http://secunia.com/advisories/10555
- http://secunia.com/advisories/10582
- http://secunia.com/advisories/10583
- http://secunia.com/advisories/20162
- http://secunia.com/advisories/20163
- http://secunia.com/advisories/20202
- http://secunia.com/advisories/20338
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
FAQ
What is CVE-2003-0984?
CVE-2003-0984 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.
How severe is CVE-2003-0984?
CVE-2003-0984 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0984?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.