Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2471

Опубликовано: 26 апр. 2011
Источник: redhat
CVSS2: 6.6
EPSS Низкий

Описание

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.

Отчет

Red Hat currently does not plan to address this issue. For details refer to: https://bugzilla.redhat.com/show_bug.cgi?id=700883#c18

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4oprofileNot affected
Red Hat Enterprise Linux 5oprofileAffected
Red Hat Enterprise Linux 6oprofileAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=712760oprofile: Local privilege escalation via shell metacharacters

EPSS

Процентиль: 19%
0.00062
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.

nvd
больше 14 лет назад

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.

debian
больше 14 лет назад

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users ...

github
больше 3 лет назад

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.

EPSS

Процентиль: 19%
0.00062
Низкий

6.6 Medium

CVSS2