4.9

CVE-2010-4243

Exploit
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.37
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.91% 0.553
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

http://secunia.com/advisories/46397
Third Party Advisory
http://www.securityfocus.com/archive/1/520102/100/0/threaded
Third Party Advisory
VDB Entry
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
Third Party Advisory
http://secunia.com/advisories/42884
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-0017.html
Third Party Advisory
http://grsecurity.net/~spender/64bit_dos.c
Broken Link
http://www.exploit-db.com/exploits/15619
Third Party Advisory
Exploit
VDB Entry
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37
Broken Link
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c
http://linux.derkeiler.com/Mailing-Lists/Kernel/2010-11/msg13278.html
Broken Link
http://lkml.org/lkml/2010/8/27/429
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/29/206
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/138
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/378
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2010/11/22/15
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2010/11/22/6
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/45004
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=625688
Third Party Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/64700
VDB Entry