Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c42f-578r-22gx

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

Ссылки

EPSS

Процентиль: 24%
0.00076
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 17 лет назад

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

redhat
почти 21 год назад

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

nvd
больше 17 лет назад

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

debian
больше 17 лет назад

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x ...

oracle-oval
больше 17 лет назад

ELSA-2008-0089: Important: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 24%
0.00076
Низкий

Дефекты

CWE-200