Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vjr-66w2-fxv8

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

EPSS

Процентиль: 69%
0.00619
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 14 лет назад

The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

redhat
больше 14 лет назад

The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

nvd
больше 14 лет назад

The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

debian
больше 14 лет назад

The proc filesystem implementation in the Linux kernel 2.6.37 and earl ...

oracle-oval
больше 13 лет назад

ELSA-2011-1530: Oracle Linux 6 kernel security, bug fix and enhancement update (MODERATE)

EPSS

Процентиль: 69%
0.00619
Низкий

Дефекты

CWE-200