CVE-2011-2490
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- nrl/opie
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631345Patch
- http://secunia.com/advisories/39966Vendor Advisory
- http://secunia.com/advisories/45136Vendor Advisory
- http://secunia.com/advisories/45448
- http://www.debian.org/security/2011/dsa-2281
- http://www.openwall.com/lists/oss-security/2011/06/22/6Exploit, Patch
- http://www.openwall.com/lists/oss-security/2011/06/23/5Exploit, Patch
- http://www.securityfocus.com/bid/48390
- https://bugzilla.novell.com/show_bug.cgi?id=698772Exploit, Patch
- https://bugzillafiles.novell.org/attachment.cgi?id=435901Patch
- https://hermes.opensuse.org/messages/10082052
- https://hermes.opensuse.org/messages/10082068
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631345Patch
- http://secunia.com/advisories/39966Vendor Advisory
- http://secunia.com/advisories/45136Vendor Advisory
- http://secunia.com/advisories/45448
- http://www.debian.org/security/2011/dsa-2281
- http://www.openwall.com/lists/oss-security/2011/06/22/6Exploit, Patch
- http://www.openwall.com/lists/oss-security/2011/06/23/5Exploit, Patch
- http://www.securityfocus.com/bid/48390
- https://bugzilla.novell.com/show_bug.cgi?id=698772Exploit, Patch
- https://bugzillafiles.novell.org/attachment.cgi?id=435901Patch
- https://hermes.opensuse.org/messages/10082052
- https://hermes.opensuse.org/messages/10082068
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.