Lucene search

K
cvelistRedhatCVELIST:CVE-2010-2524
HistorySep 08, 2010 - 7:00 p.m.

CVE-2010-2524

2010-09-0819:00:00
redhat
www.cve.org
1

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.3%

The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user’s keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a “cache stuffing” issue and MS-DFS referrals.

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.3%