- Description
- drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by leveraging root privileges to write to the /sys/kernel/debug/acpi/custom_method file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4347.
- Source
- secalert@redhat.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 3.6
- Impact score
- 4.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:P
- nvd@nist.gov
- CWE-264
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F67EAF8E-BB91-43DF-ACD8-515FC95B0988",
"versionEndIncluding": "2.6.9"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:2.6.9:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC106BDA-2EA4-41A2-AA01-6352A5C255B5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:2.6.9:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB515243-7519-4CA4-9267-D9A6798CBC49"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:2.6.9:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B672E1B6-E8E9-473F-853F-906EA56D712E"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:2.6.9:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EA23C4F-0848-4680-ACB0-CBC57D3F8C5E"
}
],
"operator": "OR"
}
]
}
]