Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-2495
HistoryOct 03, 2011 - 12:00 a.m.

CVE-2011-2495

2011-10-0300:00:00
ubuntu.com
ubuntu.com
15

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly
restrict access to /proc/#####/io files, which allows local users to obtain
sensitive I/O statistics by polling a file, as demonstrated by discovering
the length of another user’s password.

Bugs

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%