7.8

CVE-2012-0055

Exploit
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.0.0
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 11.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.653
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://www.openwall.com/lists/oss-security/2012/01/17/11
Patch
Third Party Advisory
Exploit
Mailing List
http://www.ubuntu.com/usn/USN-1363-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-1364-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-1384-1
Third Party Advisory
https://access.redhat.com/security/cve/cve-2012-0055
Third Party Advisory
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/915941
Third Party Advisory
Exploit
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-0055
Third Party Advisory
Issue Tracking