CVE-2003-0001 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 70.2% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 70.24% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-01-17 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| freebsd | freebsd |
| linux | linux kernel |
| microsoft | windows 2000 |
| microsoft | windows 2000 terminal services |
| netbsd | netbsd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco ASA < 8.4.4.6 < 8.2.5.32 - Ethernet Information Leak | 2013-06-10 |
| exploit-db | Linux Kernel 2.0.x/2.2.x/2.4.x (FreeBSD 4.x) - Network Device Driver Frame Padding Information Disclosure | 2007-03-23 |
| exploit-db | Ethernet Device Drivers Frame Padding - 'Etherleak' Infomation Leakage | 2007-03-23 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
- http://marc.info/?l=bugtraq&m=104222046632243&w=2
- http://secunia.com/advisories/7996
- http://www.atstake.com/research/advisories/2003/a010603-1.txt
- http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
- http://www.kb.cert.org/vuls/id/412115
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.osvdb.org/9962
- http://www.redhat.com/support/errata/RHSA-2003-025.html
- http://www.redhat.com/support/errata/RHSA-2003-088.html
- http://www.securityfocus.com/archive/1/305335/30/26420/threaded
- http://www.securityfocus.com/archive/1/307564/30/26270/threaded
- http://www.securitytracker.com/id/1031583
- http://www.securitytracker.com/id/1040185
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
- http://marc.info/?l=bugtraq&m=104222046632243&w=2
- http://secunia.com/advisories/7996
- http://www.atstake.com/research/advisories/2003/a010603-1.txt
- http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
→ the Explorer · watch your stack · NVD