Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1337

Опубликовано: 22 апр. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4

Описание

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

released

2.6.24-24.55
intrepid

released

2.6.27-14.35
jaunty

released

2.6.28-13.45
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.6.15-54.77
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 53%
0.00298
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

nvd
около 16 лет назад

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

debian
около 16 лет назад

The exit_notify function in kernel/exit.c in the Linux kernel before 2 ...

github
около 3 лет назад

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

oracle-oval
около 16 лет назад

ELSA-2009-0473: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 53%
0.00298
Низкий

4.4 Medium

CVSS2