Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-9645
HistoryMar 12, 2017 - 6:59 a.m.

Command injection

2017-03-1206:59:00
PRIOn knowledge base
www.prio-n.com
10

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an “ifconfig /usbserial up” command or a “mount -t /snd_pcm none /” command.

CPENameOperatorVersion
busyboxle1.22.1