Lucene search

K
cveMitreCVE-2009-0343
HistoryJan 29, 2009 - 7:30 p.m.

CVE-2009-0343

2009-01-2919:30:00
CWE-264
mitre
web.nvd.nist.gov
38
niels provos
systrace
1.6f
linux
access restrictions
bypass
cve-2009-0343
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0

Percentile

0.4%

Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.

Affected configurations

Nvd
Node
niels_provossystraceRange1.6e
OR
niels_provossystraceMatch1.1
OR
niels_provossystraceMatch1.2
OR
niels_provossystraceMatch1.3
OR
niels_provossystraceMatch1.4
OR
niels_provossystraceMatch1.5
OR
niels_provossystraceMatch1.6
OR
niels_provossystraceMatch1.6a
OR
niels_provossystraceMatch1.6b
OR
niels_provossystraceMatch1.6c
OR
niels_provossystraceMatch1.6d
AND
linuxlinux_kernelMatch_nil__nil_x86_64
VendorProductVersionCPE
niels_provossystrace*cpe:2.3:a:niels_provos:systrace:*:*:*:*:*:*:*:*
niels_provossystrace1.1cpe:2.3:a:niels_provos:systrace:1.1:*:*:*:*:*:*:*
niels_provossystrace1.2cpe:2.3:a:niels_provos:systrace:1.2:*:*:*:*:*:*:*
niels_provossystrace1.3cpe:2.3:a:niels_provos:systrace:1.3:*:*:*:*:*:*:*
niels_provossystrace1.4cpe:2.3:a:niels_provos:systrace:1.4:*:*:*:*:*:*:*
niels_provossystrace1.5cpe:2.3:a:niels_provos:systrace:1.5:*:*:*:*:*:*:*
niels_provossystrace1.6cpe:2.3:a:niels_provos:systrace:1.6:*:*:*:*:*:*:*
niels_provossystrace1.6acpe:2.3:a:niels_provos:systrace:1.6a:*:*:*:*:*:*:*
niels_provossystrace1.6bcpe:2.3:a:niels_provos:systrace:1.6b:*:*:*:*:*:*:*
niels_provossystrace1.6ccpe:2.3:a:niels_provos:systrace:1.6c:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0

Percentile

0.4%