CVE Vulnerabilities

CVE-2003-0465

Published: Aug 18, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux2.4.0 (including)2.4.0 (including)
Linux_kernelLinux2.5.0 (including)2.5.0 (including)
Red Hat Enterprise Linux 3RedHatkernel-0:2.4.21-15.EL*
Kernel-source-2.4.27Ubuntudapper*
Kernel-source-2.4.27Ubuntuedgy*

References