2.1

CVE-2007-6206

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.4.0 <= 2.4.35.2
LinuxLinux Kernel Version >= 2.6.0 < 2.6.24
LinuxLinux Kernel Version2.6.24 Update-
LinuxLinux Kernel Version2.6.24 Updaterc1
LinuxLinux Kernel Version2.6.24 Updaterc2
LinuxLinux Kernel Version2.6.24 Updaterc3
OpensuseOpensuse Version10.2
OpensuseOpensuse Version10.3
SuseLinux Enterprise Desktop Version10 Updatesp1
SuseLinux Enterprise Real Time Extension Version10 Updatesp1
SuseLinux Enterprise Server Version10 Updatesp1
RedhatEnterprise Linux Eus Version4.6
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.198
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://bugzilla.kernel.org/show_bug.cgi?id=3043
Vendor Advisory
Issue Tracking
http://www.securityfocus.com/bid/26701
Third Party Advisory
VDB Entry