Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2494

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2011-2494
Last Modified 18 Dec 2012 11:41:23
Published 13 Jun 2012 06:24:55
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2011-2494

Summary

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

Vulnerable Systems

Operating System

  • Linux Kernel 3.0.1

  • Linux Kernel 3.0.10

  • Linux Kernel 3.0.11

  • Linux Kernel 3.0.12

  • Linux Kernel 3.0.13

  • Linux Kernel 3.0.14

  • Linux Kernel 3.0.15

  • Linux Kernel 3.0.16

  • Linux Kernel 3.0.17

  • Linux Kernel 3.0.18

  • Linux Kernel 3.0.19

  • Linux Kernel 3.0.2

  • Linux Kernel 3.0.20

  • Linux Kernel 3.0.21

  • Linux Kernel 3.0.22

  • Linux Kernel 3.0.23

  • Linux Kernel 3.0.24

  • Linux Kernel 3.0.25

  • Linux Kernel 3.0.26

  • Linux Kernel 3.0.27

  • Linux Kernel 3.0.28

  • Linux Kernel 3.0.29

  • Linux Kernel 3.0.3

  • Linux Kernel 3.0.30

  • Linux Kernel 3.0.31

  • Linux Kernel 3.0.32

  • Linux Kernel 3.0.33

  • Linux Kernel 3.0.34

  • Linux Kernel 3.0.4

  • Linux Kernel 3.0.5

  • Linux Kernel 3.0.6

  • Linux Kernel 3.0.7

  • Linux Kernel 3.0.8

  • Linux Kernel 3.0.9


References

CONFIRM - https://github.com/torvalds/linux/commit/1a51410abe7d0ee4b1d112780f46df87d3621043

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1a51410abe7d0ee4b1d112780f46df87d3621043

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=716842

MLIST - [oss-security] 20110627 Re: CVE request: kernel: taskstats/procfs io infoleak

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1

SECUNIA - 48898

Related Patches

Red Hat 2011:1479-01 RHSA Important: kernel security, bug fix, and enhancement update for RHEL 5 x86

Red Hat 2011:1479-01 RHSA Important: kernel security, bug fix, and enhancement update for RHEL 5 x86_64

Novell SUSE 2012:5723 kernel security update for SLE 11 SP1 i586

Novell SUSE 2012:5732 kernel security update for SLE 11 SP1 x86_64

Novell SUSE 2012:6164 kernel security update for SLE 11 SP2 x86_64

Novell SUSE 2012:6172 kernel security update for SLE 11 SP2 i586

Novell SUSE 2012:8324 kernel security update for SLE 10 SP4 x86_64

Novell SUSE 2012:8325 kernel security update for SLE 10 SP4 i586


Last Updated: 27 May 2016 10:49:38