PT-2011-1039 · Linux+1 · Libcgroup-Debuginfo+4

Jan Lieskovsky

·

Publicado

2011-03-03

·

Atualizado

2011-09-07

·

CVE-2011-1022

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libcgroup versions prior to 0.37.1 libcgroup-pam version 0.36.1 libcgroup-devel version 0.36.1 libcgroup-debuginfo version 0.36.1
Description The issue concerns multiple vulnerabilities in the libcgroup package, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally, allowing attackers to bypass intended resource restrictions. The cgre receive netlink msg function in daemon/cgrulesengd.c does not verify that netlink messages originated in the kernel, enabling local users to exploit this weakness via crafted messages.
Recommendations For versions prior to 0.37.1, update to version 0.37.1 or later to resolve the issue. For libcgroup-pam version 0.36.1, update to a version that includes the fix for this vulnerability. For libcgroup-devel version 0.36.1, update to a version that includes the fix for this vulnerability. For libcgroup-debuginfo version 0.36.1, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the cgre receive netlink msg function until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02876
BDU:2015-05991
BDU:2015-05992
BDU:2015-05993
BDU:2015-05994
CVE-2011-1022
DSA-2193-1
OPENSUSE-SU-2024:10391-1
RHSA-2011:0320
RHSA-2011_0320

Produtos afetados

Red Hat
Libcgroup
Libcgroup-Debuginfo
Libcgroup-Devel
Libcgroup-Pam