PT-2014-9108 · Opensuse+4 · Crash+60
Prasad Pandit
·
Published
1970-01-01
·
Updated
2018-12-18
·
CVE-2014-4014
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
openSUSE kernel-default (affected versions not specified)
openSUSE kernel-source (affected versions not specified)
openSUSE kernel-debug (affected versions not specified)
openSUSE kernel-desktop (affected versions not specified)
openSUSE kernel-vanilla (affected versions not specified)
openSUSE kernel-pae (affected versions not specified)
openSUSE kernel-ec2 (affected versions not specified)
openSUSE kernel-trace (affected versions not specified)
openSUSE kernel-xen (affected versions not specified)
openSUSE kernel-default-devel (affected versions not specified)
openSUSE kernel-desktop-devel (affected versions not specified)
openSUSE kernel-pae-devel (affected versions not specified)
openSUSE kernel-vanilla-devel (affected versions not specified)
openSUSE kernel-ec2-devel (affected versions not specified)
openSUSE kernel-trace-devel (affected versions not specified)
openSUSE kernel-xen-devel (affected versions not specified)
openSUSE libipset3 (affected versions not specified)
openSUSE ipset (affected versions not specified)
openSUSE ipset-kmp-default (affected versions not specified)
openSUSE ipset-kmp-pae (affected versions not specified)
openSUSE ipset-kmp-xen (affected versions not specified)
openSUSE ndiswrapper (affected versions not specified)
openSUSE ndiswrapper-kmp-default (affected versions not specified)
openSUSE ndiswrapper-kmp-pae (affected versions not specified)
openSUSE ndiswrapper-kmp-desktop (affected versions not specified)
openSUSE pcfclock (affected versions not specified)
openSUSE pcfclock-kmp-default (affected versions not specified)
openSUSE pcfclock-kmp-pae (affected versions not specified)
openSUSE pcfclock-kmp-desktop (affected versions not specified)
openSUSE vhba-kmp-default (affected versions not specified)
openSUSE vhba-kmp-pae (affected versions not specified)
openSUSE vhba-kmp-xen (affected versions not specified)
openSUSE xtables-addons (affected versions not specified)
openSUSE xtables-addons-kmp-default (affected versions not specified)
openSUSE xtables-addons-kmp-pae (affected versions not specified)
openSUSE xtables-addons-kmp-xen (affected versions not specified)
openSUSE xtables-addons-kmp-desktop (affected versions not specified)
openSUSE iscsitarget (affected versions not specified)
openSUSE iscsitarget-kmp-default (affected versions not specified)
openSUSE iscsitarget-kmp-pae (affected versions not specified)
openSUSE iscsitarget-kmp-xen (affected versions not specified)
openSUSE iscsitarget-kmp-desktop (affected versions not specified)
openSUSE cloop (affected versions not specified)
openSUSE cloop-kmp-default (affected versions not specified)
openSUSE cloop-kmp-pae (affected versions not specified)
openSUSE cloop-kmp-xen (affected versions not specified)
openSUSE cloop-kmp-desktop (affected versions not specified)
openSUSE hdjmod (affected versions not specified)
openSUSE hdjmod-kmp-default (affected versions not specified)
openSUSE hdjmod-kmp-pae (affected versions not specified)
openSUSE hdjmod-kmp-xen (affected versions not specified)
openSUSE hdjmod-kmp-desktop (affected versions not specified)
openSUSE crash (affected versions not specified)
openSUSE crash-kmp-default (affected versions not specified)
openSUSE crash-kmp-pae (affected versions not specified)
openSUSE crash-kmp-xen (affected versions not specified)
openSUSE crash-kmp-desktop (affected versions not specified)
Description
The Linux kernel has multiple vulnerabilities that can be exploited to compromise the confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Local users can bypass intended chmod restrictions by creating a user namespace and setting the setgid bit on a file with group ownership of root.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Suse
Ubuntu
Cloop
Cloop-Kmp-Default
Cloop-Kmp-Desktop
Cloop-Kmp-Pae
Cloop-Kmp-Xen
Crash
Crash-Kmp-Default
Crash-Kmp-Desktop
Crash-Kmp-Pae
Crash-Kmp-Xen
Hdjmod
Hdjmod-Kmp-Default
Hdjmod-Kmp-Desktop
Hdjmod-Kmp-Pae
Hdjmod-Kmp-Xen
Ipset
Ipset-Kmp-Default
Ipset-Kmp-Pae
Ipset-Kmp-Xen
Iscsitarget
Iscsitarget-Kmp-Default
Iscsitarget-Kmp-Desktop
Iscsitarget-Kmp-Pae
Iscsitarget-Kmp-Xen
Kernel-Debug
Kernel-Default
Kernel-Default-Devel
Kernel-Desktop
Kernel-Desktop-Devel
Kernel-Ec2
Kernel-Ec2-Devel
Kernel-Pae
Kernel-Pae-Devel
Kernel-Source
Kernel-Trace
Kernel-Trace-Devel
Kernel-Vanilla
Kernel-Vanilla-Devel
Kernel-Xen
Kernel-Xen-Devel
Libipset3
Ndiswrapper
Ndiswrapper-Kmp-Default
Ndiswrapper-Kmp-Desktop
Ndiswrapper-Kmp-Pae
Pcfclock
Pcfclock-Kmp-Default
Pcfclock-Kmp-Desktop
Pcfclock-Kmp-Pae
Vhba-Kmp-Default
Vhba-Kmp-Pae
Vhba-Kmp-Xen
Xtables-Addons
Xtables-Addons-Kmp-Default
Xtables-Addons-Kmp-Desktop
Xtables-Addons-Kmp-Pae
Xtables-Addons-Kmp-Xen