CVE-2014-0181
Published Apr 27, 2014
Last updated 2 years ago
Overview
- Description
- The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BCA1B8AC-8CF2-444F-9A49-273B9BBF00BC", "versionEndIncluding": "3.14.1" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCE4D64E-8C4B-4F21-A9B0-90637C85C1D0" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E22FF518-9616-4EAD-AF6B-9CC930916F37" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54D669D4-6D7E-449D-80C1-28FA44F06FFE" }, { "criteria": "cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DB41B45-D94D-4A58-88B0-B3EC3EC350E2" }, { "criteria": "cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:*", "vulnerable": true, "matchCriteriaId": "35BBD83D-BDC7-4678-BE94-639F59281139" }, { "criteria": "cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:*:*:*", "vulnerable": true, "matchCriteriaId": "67960FB9-13D1-4DEE-8158-31BF31BCBE6F" }, { "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93AD897C-C9F7-4B4D-BC39-5E13920383D4" } ], "operator": "OR" } ] } ]