Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3725

Опубликовано: 06 нояб. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2

Описание

The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.32-3.4
hardy

released

2.6.24-26.64
intrepid

released

2.6.27-16.44
jaunty

released

2.6.28-17.58
karmic

released

2.6.31-16.52
upstream

released

2.6.32

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 14%
0.00046
Низкий

7.2 High

CVSS2

Связанные уязвимости

nvd
около 16 лет назад

The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.

debian
около 16 лет назад

The connector layer in the Linux kernel before 2.6.31.5 does not requi ...

github
больше 3 лет назад

The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.

EPSS

Процентиль: 14%
0.00046
Низкий

7.2 High

CVSS2