Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2929

Опубликовано: 07 нояб. 2013
Источник: redhat
CVSS2: 1.9

Описание

The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.

A flaw was found in the way the get_dumpable() function return value was interpreted in the ptrace subsystem of the Linux kernel. When 'fs.suid_dumpable' was set to 2, a local, unprivileged local user could use this flaw to bypass intended ptrace restrictions and obtain potentially sensitive information.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1028148kernel: exec/ptrace: get_dumpable() incorrect tests

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.

nvd
больше 11 лет назад

The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.

debian
больше 11 лет назад

The Linux kernel before 3.12.2 does not properly use the get_dumpable ...

github
около 3 лет назад

The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.

fstec
больше 11 лет назад

Уязвимость операционной системы Linux, приводящая к раскрытию информации

1.9 Low

CVSS2