Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3725
HistoryNov 06, 2009 - 12:00 a.m.

CVE-2009-3725

2009-11-0600:00:00
ubuntu.com
ubuntu.com
13

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

10.1%

The connector layer in the Linux kernel before 2.6.31.5 does not require
the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb,
(2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to
bypass intended access restrictions and gain privileges via calls to
functions in these subsystems.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchlinux<Β 2.6.24-26.64UNKNOWN
ubuntu8.10noarchlinux<Β 2.6.27-16.44UNKNOWN
ubuntu9.04noarchlinux<Β 2.6.28-17.58UNKNOWN
ubuntu9.10noarchlinux<Β 2.6.31-16.52UNKNOWN

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

10.1%