4.6

CVE-2008-4210

Exploit
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.21.7
LinuxLinux Kernel Version2.2.27
LinuxLinux Kernel Version2.4.36
LinuxLinux Kernel Version2.4.36.1
LinuxLinux Kernel Version2.4.36.2
LinuxLinux Kernel Version2.4.36.3
LinuxLinux Kernel Version2.4.36.4
LinuxLinux Kernel Version2.4.36.5
LinuxLinux Kernel Version2.4.36.6
LinuxLinux Kernel Version2.6
LinuxLinux Kernel Version2.6.18
LinuxLinux Kernel Version2.6.18 Updaterc1
LinuxLinux Kernel Version2.6.18 Updaterc2
LinuxLinux Kernel Version2.6.18 Updaterc3
LinuxLinux Kernel Version2.6.18 Updaterc4
LinuxLinux Kernel Version2.6.18 Updaterc5
LinuxLinux Kernel Version2.6.18 Updaterc6
LinuxLinux Kernel Version2.6.18 Updaterc7
LinuxLinux Kernel Version2.6.19.4
LinuxLinux Kernel Version2.6.19.5
LinuxLinux Kernel Version2.6.19.6
LinuxLinux Kernel Version2.6.19.7
LinuxLinux Kernel Version2.6.20.16
LinuxLinux Kernel Version2.6.20.17
LinuxLinux Kernel Version2.6.20.18
LinuxLinux Kernel Version2.6.20.19
LinuxLinux Kernel Version2.6.20.20
LinuxLinux Kernel Version2.6.20.21
LinuxLinux Kernel Version2.6.21.5
LinuxLinux Kernel Version2.6.21.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.14% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
http://secunia.com/advisories/33280
http://www.redhat.com/support/errata/RHSA-2008-0787.html
http://secunia.com/advisories/32485
http://www.redhat.com/support/errata/RHSA-2008-0957.html
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://secunia.com/advisories/32759
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22
http://rhn.redhat.com/errata/RHSA-2008-0972.html
http://secunia.com/advisories/32799
http://secunia.com/advisories/33201
http://www.redhat.com/support/errata/RHSA-2008-0973.html
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html
http://secunia.com/advisories/32237
http://secunia.com/advisories/32356
http://www.debian.org/security/2008/dsa-1653
http://secunia.com/advisories/32918
http://www.ubuntu.com/usn/usn-679-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:220
http://secunia.com/advisories/32344
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
http://bugzilla.kernel.org/show_bug.cgi?id=8420
http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=7b82dc0e64e93f430182f36b46b79fcee87d3532
http://www.openwall.com/lists/oss-security/2008/09/24/5
http://www.openwall.com/lists/oss-security/2008/09/24/8
http://www.securityfocus.com/bid/31368
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=463661
https://exchange.xforce.ibmcloud.com/vulnerabilities/45539
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6386
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9511