CVE-2010-4347
CVE-2010-4347
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/15774/unverifiedexploitdbwww.exploit-db.com/exploits/15774unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ed3aada1bf34c5a9e98af167f125f8a740fc726ahttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/12/15/3http://openwall.com/lists/oss-security/2010/12/15/7https://bugzilla.redhat.com/show_bug.cgi?id=663542http://secunia.com/advisories/42778https://exchange.xforce.ibmcloud.com/vulnerabilities/64155http://www.exploit-db.com/exploits/15774/http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36.2http://www.securityfocus.com/bid/45408http://www.vupen.com/english/advisories/2011/0012