CVE-2009-2691

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=00f89d218523b9bf6b522349c039d5ac80aa536d

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13f0feafa6b8aead57a2a328e2fca6a5828bf286

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=704b836cbf19e885f8366bccb2e4b0474346c02d

http://lkml.org/lkml/2009/6/23/652

http://lkml.org/lkml/2009/6/23/653

http://marc.info/?l=linux-kernel&m=124718946021193

http://marc.info/?l=linux-kernel&m=124718949821250

http://secunia.com/advisories/36265

http://secunia.com/advisories/36501

http://www.debian.org/security/2010/dsa-2005

http://www.openwall.com/lists/oss-security/2009/08/11/1

http://www.securityfocus.com/bid/36019

http://www.vupen.com/english/advisories/2009/2246

https://bugzilla.redhat.com/show_bug.cgi?id=516171

https://exchange.xforce.ibmcloud.com/vulnerabilities/52401

https://rhn.redhat.com/errata/RHSA-2009-1540.html

https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01256.html

Details

Source: MITRE

Published: 2009-08-14

Updated: 2017-08-17

Type: CWE-200

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
67955Oracle Linux 3 : kernel (ELSA-2009-1550)NessusOracle Linux Local Security Checks
high
67953Oracle Linux 5 : kernel (ELSA-2009-1548)NessusOracle Linux Local Security Checks
high
67952Oracle Linux 4 : kernel (ELSA-2009-1541)NessusOracle Linux Local Security Checks
high
67070CentOS 3 : kernel (CESA-2009:1550)NessusCentOS Local Security Checks
high
67068CentOS 5 : kernel (CESA-2009:1548)NessusCentOS Local Security Checks
high
67067CentOS 4 : kernel (CESA-2009:1541)NessusCentOS Local Security Checks
high
44951Debian DSA-2005-1 : linux-2.6.24 - privilege escalation/denial of service/sensitive memory leakNessusDebian Local Security Checks
critical
42360RHEL 3 : kernel (RHSA-2009:1550)NessusRed Hat Local Security Checks
high
42358RHEL 5 : kernel (RHSA-2009:1548)NessusRed Hat Local Security Checks
high
42357RHEL 4 : kernel (RHSA-2009:1541)NessusRed Hat Local Security Checks
high
40780Fedora 11 : kernel-2.6.29.6-217.2.16.fc11 (2009-9044)NessusFedora Local Security Checks
high