PT-2010-5666 · Linux+2 · Linux Kernel+5

Segoon

+1

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2011-2495

CVSS v2.0

5.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise versions prior to 2.6.39.4 btrfs-kmp-xen (affected versions not specified) btrfs-kmp-pae (affected versions not specified) kernel-desktop-devel (affected versions not specified)
Description The issue allows local users to obtain sensitive information, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be performed locally. In the Linux kernel, the fs/proc/base.c file does not properly restrict access to /proc/#####/io files, enabling local users to obtain sensitive I/O statistics by polling a file. This could be used to discover the length of another user's password.
Recommendations For SUSE Linux Enterprise versions prior to 2.6.39.4, update to version 2.6.39.4 or later to resolve the issue. For btrfs-kmp-xen, btrfs-kmp-pae, and kernel-desktop-devel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2015-04341
BDU:2015-04342
BDU:2015-04343
CVE-2011-2495
DSA-2303-1
DSA-2310-1
RHSA-2011:1189
RHSA-2011:1212
RHSA-2011:1253
RHSA-2011:1813
RHSA-2011_1189
RHSA-2011_1212

Affected Products

Linux Kernel
Red Hat
Suse Linux Enterprise
Btrfs-Kmp-Pae
Btrfs-Kmp-Xen
Kernel-Desktop-Devel