init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.
2005-09-01T22:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 3.0 | Yes |