PT-2009-6740 · Suse+1 · Suse Linux Enterprise+3

Eugene Teo

·

Published

1970-01-01

·

Updated

2012-03-19

·

CVE-2009-0835

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions module-init-tools versions (affected versions not specified) module-init-tools-debuginfo versions (affected versions not specified) module-init-tools-debugsource versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the module-init-tools package of SUSE Linux Enterprise and openSUSE operating systems, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited locally. Additionally, a vulnerability in the secure computing function of the seccomp subsystem in the Linux kernel is related to errors in handling 32-bit and 64-bit processes, allowing a local attacker to bypass existing access restrictions using a specially crafted system call.
Recommendations For module-init-tools, consider disabling the package until a patch is available. For module-init-tools-debuginfo, restrict access to the package to minimize the risk of exploitation. For module-init-tools-debugsource, avoid using the package in sensitive environments until the issue is resolved. As a temporary workaround, consider disabling the secure computing function in the seccomp subsystem until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04356
BDU:2015-04357
BDU:2015-04358
BDU:2015-05176
BDU:2015-05177
BDU:2015-05178
BDU:2016-01578
CVE-2009-0835
DSA-1800-1
RHSA-2009:0451

Affected Products

Linux Kernel
Suse Linux Enterprise
Module-Init-Tools
Opensuse