PT-2017-13274 · Linux+5 · Linux Kernel+5

Otto Ebeling

·

Publicado

2017-08-27

·

Atualizado

2018-07-09

·

CVE-2017-14140

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.9
Description The issue allows a local attacker to learn the memory layout of a setuid executable despite Address Space Layout Randomization (ASLR). This is due to the move pages system call not checking the effective uid of the target process.
Recommendations For Linux kernel versions prior to 4.12.9, update to version 4.12.9 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2114
ALT-PU-2018-1991
CESA-2018_1062
CVE-2017-14140
DLA-1099-1
DSA-3981-1
RHSA-2018:0676
RHSA-2018:1062
RHSA-2018_0676
RHSA-2018_1062
SUSE-SU-2017:2694-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
SUSE-SU-2017:3265-1
SUSE-SU-2018:0040-1
USN-3444-1
USN-3444-2
USN-3583-1
USN-3583-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu