Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4141

Опубликовано: 16 дек. 2009
Источник: redhat
CVSS2: 7.2
EPSS Низкий

Описание

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

Отчет

This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit 233e70f4 that introduced the problem.

Дополнительная информация

Статус:

Important
Дефект:
CWE-672->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=547906kernel: create_elf_tables can leave urandom in a bad state

EPSS

Процентиль: 32%
0.00117
Низкий

7.2 High

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

nvd
больше 15 лет назад

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

debian
больше 15 лет назад

Use-after-free vulnerability in the fasync_helper function in fs/fcntl ...

github
около 3 лет назад

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

oracle-oval
больше 15 лет назад

ELSA-2010-0046: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 32%
0.00117
Низкий

7.2 High

CVSS2