Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4346

Опубликовано: 22 дек. 2010
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 2.6.37 (исключая)
cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.37:rc5:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00058
Низкий

2.1 Low

CVSS2

Дефекты

CWE-476

Связанные уязвимости

ubuntu
больше 14 лет назад

The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.

redhat
больше 14 лет назад

The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.

debian
больше 14 лет назад

The install_special_mapping function in mm/mmap.c in the Linux kernel ...

github
около 3 лет назад

The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.

oracle-oval
около 14 лет назад

ELSA-2011-0429: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 18%
0.00058
Низкий

2.1 Low

CVSS2

Дефекты

CWE-476