Описание
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
hardy | DNE | |
karmic | ignored | end of life |
lucid | released | 2.11.1-0ubuntu7.10 |
maverick | released | 2.12.1-0ubuntu10.4 |
natty | released | 2.13-0ubuntu13.1 |
oneiric | not-affected | 2.13-20ubuntu5 |
upstream | released | 2.13-8 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | |
hardy | released | 2.7-10ubuntu8.1 |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
upstream | needs-triage |
Показывать по
EPSS
3.3 Low
CVSS2
Связанные уязвимости
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 ...
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
ELSA-2011-1526: glibc security, bug fix, and enhancement update (LOW)
EPSS
3.3 Low
CVSS2