{"api_version":"1","generated_at":"2026-07-23T05:20:19+00:00","cve":"CVE-2003-0019","urls":{"html":"https://cve.report/CVE-2003-0019","api":"https://cve.report/api/cve/CVE-2003-0019.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0019","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0019"},"summary":{"title":"CVE-2003-0019","description":"uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-02-19 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.iss.net/security_center/static/11276.php","name":"http://www.iss.net/security_center/static/11276.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database:linux-umlnet-gain-privileges(11276): Red Hat Linux uml_net utility could allow an attacker to gain privileges","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2003-056.html","name":"http://www.redhat.com/support/errata/RHSA-2003-056.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/n-044.shtml","name":"http://www.ciac.org/ciac/bulletins/n-044.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"N-044: Red Hat Updated kernel-utils Packages Fix setuid Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6801","name":"http://www.securityfocus.com/bid/6801","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Linux User Mode Linux SetUID Installation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/134025","name":"http://www.kb.cert.org/vuls/id/134025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#134025","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0019","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0019","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"19","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"linux","cpe6":"8.0","cpe7":"*","cpe8":"i386","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:36:25.329Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"linux-umlnet-gain-privileges(11276)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/11276.php"},{"name":"VU#134025","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/134025"},{"name":"N-044","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/n-044.shtml"},{"name":"RHSA-2003:056","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2003-056.html"},{"name":"6801","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6801"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-13T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"linux-umlnet-gain-privileges(11276)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/11276.php"},{"name":"VU#134025","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/134025"},{"name":"N-044","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/n-044.shtml"},{"name":"RHSA-2003:056","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2003-056.html"},{"name":"6801","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6801"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0019","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"linux-umlnet-gain-privileges(11276)","refsource":"XF","url":"http://www.iss.net/security_center/static/11276.php"},{"name":"VU#134025","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/134025"},{"name":"N-044","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/n-044.shtml"},{"name":"RHSA-2003:056","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2003-056.html"},{"name":"6801","refsource":"BID","url":"http://www.securityfocus.com/bid/6801"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0019","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2003-01-07T00:00:00.000Z","dateUpdated":"2024-08-08T01:36:25.329Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-02-19 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:linux:8.0:*:i386:*:*:*:*:*","matchCriteriaId":"4D1E6298-EDF5-438F-8DFD-16A514CB938A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"19","Ordinal":"1","Title":"CVE-2003-0019","CVE":"CVE-2003-0019","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"19","Ordinal":"1","NoteData":"uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.","Type":"Description","Title":"CVE-2003-0019"},{"CveYear":"2003","CveId":"19","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"19","Ordinal":"3","NoteData":"2007-11-12","Type":"Other","Title":"Modified"}]}}}