Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9645

Опубликовано: 12 мар. 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*
Версия до 1.22.1 (включая)

EPSS

Процентиль: 59%
0.00375
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

redhat
около 11 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
debian
почти 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 ...

suse-cvrf
больше 10 лет назад

Security update for busybox

CVSS3: 5.5
github
больше 3 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

EPSS

Процентиль: 59%
0.00375
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20