2.1

CVE-2011-1022

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Balbir SinghLibcgroup Version <= 0.37
Balbir SinghLibcgroup Version0.1b
Balbir SinghLibcgroup Version0.1c
Balbir SinghLibcgroup Version0.2
Balbir SinghLibcgroup Version0.3
Balbir SinghLibcgroup Version0.31
Balbir SinghLibcgroup Version0.32
Balbir SinghLibcgroup Version0.32.1
Balbir SinghLibcgroup Version0.32.2
Balbir SinghLibcgroup Version0.33
Balbir SinghLibcgroup Version0.34
Balbir SinghLibcgroup Version0.35
Balbir SinghLibcgroup Version0.35.1
Balbir SinghLibcgroup Version0.36
Balbir SinghLibcgroup Version0.36.1
Balbir SinghLibcgroup Version0.36.2
Balbir SinghLibcgroup Version0.37 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.302
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056683.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056734.html
http://lists.opensuse.org/opensuse-updates/2011-04/msg00027.html
http://secunia.com/advisories/43611
Vendor Advisory
http://secunia.com/advisories/43758
Vendor Advisory
http://secunia.com/advisories/43891
http://secunia.com/advisories/44093
http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/download
Patch
http://www.debian.org/security/2011/dsa-2193
http://www.redhat.com/support/errata/RHSA-2011-0320.html
http://www.vupen.com/english/advisories/2011/0679
Vendor Advisory
http://www.vupen.com/english/advisories/2011/0774
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987
Patch
http://openwall.com/lists/oss-security/2011/02/25/11
Patch
http://openwall.com/lists/oss-security/2011/02/25/12
Patch
http://openwall.com/lists/oss-security/2011/02/25/14
http://openwall.com/lists/oss-security/2011/02/25/6
Patch
http://openwall.com/lists/oss-security/2011/02/25/9
Patch
http://sourceforge.net/mailarchive/message.php?msg_id=26598749
Patch
http://sourceforge.net/mailarchive/message.php?msg_id=27102603
Patch
http://www.securityfocus.com/bid/46578
http://www.securitytracker.com/id?1025157
https://bugzilla.redhat.com/show_bug.cgi?id=680409
Patch