2.1

CVE-2011-1022

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Balbir SinghLibcgroup Version <= 0.37
Balbir SinghLibcgroup Version0.1b
Balbir SinghLibcgroup Version0.1c
Balbir SinghLibcgroup Version0.2
Balbir SinghLibcgroup Version0.3
Balbir SinghLibcgroup Version0.31
Balbir SinghLibcgroup Version0.32
Balbir SinghLibcgroup Version0.32.1
Balbir SinghLibcgroup Version0.32.2
Balbir SinghLibcgroup Version0.33
Balbir SinghLibcgroup Version0.34
Balbir SinghLibcgroup Version0.35
Balbir SinghLibcgroup Version0.35.1
Balbir SinghLibcgroup Version0.36
Balbir SinghLibcgroup Version0.36.1
Balbir SinghLibcgroup Version0.36.2
Balbir SinghLibcgroup Version0.37 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.