Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2494

Опубликовано: 21 июн. 2011
Источник: redhat
CVSS2: 2.1

Описание

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

Отчет

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not provide support for the Taskstats interface. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1479.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 5kernelFixedRHSA-2011:147929.11.2011
Red Hat Enterprise Linux 6kernelFixedRHSA-2011:146522.11.2011
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2012:001010.01.2012

Показывать по

Дополнительная информация

Статус:

Low

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

nvd
около 13 лет назад

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

debian
около 13 лет назад

kernel/taskstats.c in the Linux kernel before 3.1 allows local users t ...

github
около 3 лет назад

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

fstec
около 14 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к статистике ввода-вывода

2.1 Low

CVSS2