Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4270

Опубликовано: 06 окт. 2013
Источник: redhat
CVSS2: 4.7
EPSS Низкий

Описание

The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.

Отчет

This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelAffected
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2014:010028.01.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1027752kernel: net: permissions flaw in /proc/sys/net

EPSS

Процентиль: 13%
0.00044
Низкий

4.7 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.

nvd
около 12 лет назад

The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.

debian
около 12 лет назад

The net_ctl_permissions function in net/sysctl_net.c in the Linux kern ...

github
больше 3 лет назад

The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.

oracle-oval
почти 12 лет назад

ELSA-2014-3002: Unbreakable Enterprise kernel security and bug fix update (Unbreakable Enterprise Kernel Release 3 QU1) (IMPORTANT)

EPSS

Процентиль: 13%
0.00044
Низкий

4.7 Medium

CVSS2

Уязвимость CVE-2013-4270