PT-2019-5360 · Linux+4 · Linux Kernel+4

Publicado

2019-03-05

·

Atualizado

2024-08-04

·

CVE-2019-11191

CVSS v3.1

2.5

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.0.7
Description The issue allows local users to bypass ASLR on setuid a.out programs because install exec creds() is called too late in load aout binary() in fs/binfmt aout.c, and thus the ptrace may access() check has a race condition when reading /proc/pid/stat. The software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1665
ALT-PU-2019-1710
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-02567
CVE-2019-11191
ECHO-1FD0-03C0-B9EF
OPENSUSE-SU-2019_1570-1
USN-4006-1
USN-4006-2
USN-4007-1
USN-4007-2
USN-4008-1
USN-4008-3

Produtos afetados

Alt Linux
Debian
Linux Kernel
Suse
Ubuntu