Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9645

Опубликовано: 12 мар. 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*
Версия до 1.22.1 (включая)

EPSS

Процентиль: 47%
0.00635
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

redhat
больше 11 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
debian
больше 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 ...

suse-cvrf
около 11 лет назад

Security update for busybox

CVSS3: 5.5
github
больше 4 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

EPSS

Процентиль: 47%
0.00635
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20