[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253650

 
 

909

 
 

197367

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1883Date: (C)2009-09-18   (M)2024-02-22


The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-36759
SECUNIA-37105
RHSA-2009:1438
SUSE-SA:2010:013
USN-852-1
http://www.openwall.com/lists/oss-security/2009/09/15/1
http://www.openwall.com/lists/oss-security/2009/09/15/3
https://bugzilla.redhat.com/show_bug.cgi?id=505983
oval:org.mitre.oval:def:9513

CPE    1
cpe:/o:linux:linux_kernel:2.6.9
CWE    1
CWE-264
OVAL    5
oval:org.secpod.oval:def:202781
oval:org.secpod.oval:def:700430
oval:org.secpod.oval:def:600455
oval:org.secpod.oval:def:500688
...

© SecPod Technologies