PT-2009-6740 · Suse+1 · Suse Linux Enterprise+3

Eugene Teo

·

Publicado

1970-01-01

·

Atualizado

2012-03-19

·

CVE-2009-0835

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions module-init-tools versions (affected versions not specified) module-init-tools-debuginfo versions (affected versions not specified) module-init-tools-debugsource versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the module-init-tools package of SUSE Linux Enterprise and openSUSE operating systems, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited locally. Additionally, a vulnerability in the secure computing function of the seccomp subsystem in the Linux kernel is related to errors in handling 32-bit and 64-bit processes, allowing a local attacker to bypass existing access restrictions using a specially crafted system call.
Recommendations For module-init-tools, consider disabling the package until a patch is available. For module-init-tools-debuginfo, restrict access to the package to minimize the risk of exploitation. For module-init-tools-debugsource, avoid using the package in sensitive environments until the issue is resolved. As a temporary workaround, consider disabling the secure computing function in the seccomp subsystem until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04356
BDU:2015-04357
BDU:2015-04358
BDU:2015-05176
BDU:2015-05177
BDU:2015-05178
BDU:2016-01578
CVE-2009-0835
DSA-1800-1
RHSA-2009:0451

Produtos afetados

Linux Kernel
Suse Linux Enterprise
Module-Init-Tools
Opensuse