Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-2365
HistoryJun 30, 2008 - 12:00 a.m.

CVE-2008-2365

2008-06-3000:00:00
ubuntu.com
ubuntu.com
16

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

10.1%

Race condition in the ptrace and utrace support in the Linux kernel 2.6.9
through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local
users to cause a denial of service (oops) via a long series of
PTRACE_ATTACH ptrace calls to another user’s process that trigger a
conflict between utrace_detach and report_quiescent, related to β€œlate
ptrace_may_attach() check” and β€œrace around &dead_engine_ops setting,” a
different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this
issue might only affect kernel versions before 2.6.16.x.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchlinux-source-2.6.15<Β 2.6.15-52.69UNKNOWN

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

10.1%