← volver
CVE-2008-4210

CVE-2008-4210

23Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendepss 2.1%
de la publicación al arma28 días
Publicada en NVD29 sept
1ª PoC+28d
probabilidad de explotación
2.1%top 20% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.