Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9645

Опубликовано: 19 нояб. 2014
Источник: redhat
CVSS2: 1

Описание

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

Отчет

This issue affects the versions of busyboxas shipped with Red Hat Enterprise Linux 4, 5 and 6. Red Hat Product Security has rated this issue as having a low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4busyboxWill not fix
Red Hat Enterprise Linux 5busyboxWill not fix
Red Hat Enterprise Linux 6busyboxWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-228
https://bugzilla.redhat.com/show_bug.cgi?id=1185707busybox: unprivileged arbitrary module load via basename abuse

1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
nvd
больше 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

CVSS3: 5.5
debian
больше 9 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 ...

suse-cvrf
около 11 лет назад

Security update for busybox

CVSS3: 5.5
github
больше 4 лет назад

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

1 Low

CVSS2