HIGH
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes
Published Jul 27, 2011
7.2
HIGHCVSS 2.0
EPSS 0.53%
Description
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631345 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/39966 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/45136 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/45448 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2011/dsa-2281 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2011/06/22/6 mailing-listx_refsource_MLISTExploitPatch
- http://www.openwall.com/lists/oss-security/2011/06/23/5 mailing-listx_refsource_MLISTExploitPatch
- http://www.securityfocus.com/bid/48390 vdb-entryx_refsource_BID
- https://bugzilla.novell.com/show_bug.cgi?id=698772 x_refsource_CONFIRMExploitPatch
- https://bugzillafiles.novell.org/attachment.cgi?id=435901 x_refsource_CONFIRMPatch
- https://hermes.opensuse.org/messages/10082052 vendor-advisoryx_refsource_SUSE
- https://hermes.opensuse.org/messages/10082068 vendor-advisoryx_refsource_SUSE
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2011
Updated Aug 6, 2024
Reserved Jun 15, 2011
Link CVE-2011-2490
CISA Vulnrichment
Updated n/a