PT-2010-4719 · Linux+1 · Linux Kernel+1

Ben Hawkes

·

Publicado

2010-09-22

·

Atualizado

2024-06-15

·

CVE-2010-3301

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.36-rc4-git2
Description The issue is related to the IA32 system call emulation functionality in the Linux kernel on the x86 64 platform. It does not properly zero extend the %eax register after using the 32-bit entry path to ptrace, allowing local users to gain privileges. This is achieved by triggering an out-of-bounds access to the system call table using the %rax register.
Recommendations For Linux kernel versions prior to 2.6.36-rc4-git2, update to version 2.6.36-rc4-git2 or later to resolve the issue.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3301
OPENSUSE-SU-2024:10128-1
RHSA-2010:0842
RHSA-2010_0842

Produtos afetados

Linux Kernel
Red Hat