Back to search
CVE-2011-2495
Published: Jun 13, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20110627 Re: CVE request: kernel: taskstats/procfs io infoleak
mailing-list
x_refsource_MLIST
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.4
x_refsource_CONFIRM
RHSA-2011:1212
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=716825
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now