PT-2012-1507 · Linux+2 · Linux Kernel+2

Segoon

+1

·

Published

2011-05-10

·

Updated

2023-02-13

·

CVE-2011-1080

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.39
Description The issue allows local users to obtain potentially sensitive information from kernel stack memory. This is possible because the do replace function in net/bridge/netfilter/ebtables.c does not ensure that a certain name field ends with a '0' character. A local user with the CAP NET ADMIN capability can replace a table and then read a modprobe command line to exploit this.
Recommendations For versions prior to 2.6.39, update to version 2.6.39 or later to resolve the issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2011-1080
DSA-2240-1
DSA-2264-1
OPENSUSE-SU-2012_0236-1
RHSA-2011:0498
RHSA-2011:0500
RHSA-2011:0833
RHSA-2011_0498
RHSA-2011_0833

Affected Products

Linux Kernel
Red Hat
Suse