4.9

CVE-2010-4243

Exploit

fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.37
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.403
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://www.exploit-db.com/exploits/15619
Third Party Advisory
Exploit
VDB Entry
http://lkml.org/lkml/2010/8/27/429
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/29/206
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/138
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/378
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2010/11/22/15
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2010/11/22/6
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/45004
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=625688
Third Party Advisory
Issue Tracking