Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2691

Опубликовано: 10 июл. 2009
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

Отчет

We currently have no plans to fix this flaw in Red Hat Enterprise Linux 3, 4, and 5 as it is not possible to trigger the information leak if the suid_dumpable tunable is set to zero (which is the default).

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=516171kernel: /proc/$pid/maps visible during initial setuid ELF loading

EPSS

Процентиль: 18%
0.00057
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

nvd
около 16 лет назад

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

debian
около 16 лет назад

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30. ...

github
больше 3 лет назад

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

EPSS

Процентиль: 18%
0.00057
Низкий

2.1 Low

CVSS2

Уязвимость CVE-2009-2691