Back to search
CVE-2011-1020
Published: Feb 28, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
kernel-procpid-security-bypass(65693)
vdb-entry
x_refsource_XF
8107
third-party-advisory
x_refsource_SREASON
43496
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20110224 CVE request: kernel: /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[oss-security] 20110225 Re: CVE request: kernel: /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
46567
vdb-entry
x_refsource_BID
[linux-kernel] 20110207 [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec
mailing-list
x_refsource_MLIST
20110122 Proc filesystem and SUID-Binaries
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now