Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9645

Опубликовано: 19 нояб. 2014
Источник: redhat
CVSS2: 1
EPSS Низкий

Описание

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

Отчет

This issue affects the versions of busyboxas shipped with Red Hat Enterprise Linux 4, 5 and 6. Red Hat Product Security has rated this issue as having a low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4busyboxWill not fix
Red Hat Enterprise Linux 5busyboxWill not fix
Red Hat Enterprise Linux 6busyboxWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-228
https://bugzilla.redhat.com/show_bug.cgi?id=1185707busybox: unprivileged arbitrary module load via basename abuse

EPSS

Процентиль: 59%
0.00375
Низкий

1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
nvd
почти 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
debian
почти 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 ...

suse-cvrf
больше 10 лет назад

Security update for busybox

CVSS3: 5.5
github
больше 3 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

EPSS

Процентиль: 59%
0.00375
Низкий

1 Low

CVSS2