CVE-2011-4080 - CERT CVE
ID CVE-2011-4080
Sažetak The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.
Reference
CVSS
Base: 4.0
Impact: 6.9
Exploitability:1.9
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:L/AC:H/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 13-02-2023 - 04:32
Objavljeno 24-05-2012 - 23:55