Total vulnerabilities in the database
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | 2.6.39-rc7 | 2.6.39-rc7.x |
linux / linux_kernel | 2.6.39-rc6 | 2.6.39-rc6.x |
linux / linux_kernel | 2.6.39-rc4 | 2.6.39-rc4.x |
linux / linux_kernel | 2.6.39.1 | 2.6.39.1.x |
linux / linux_kernel | 2.6.39-rc1 | 2.6.39-rc1.x |
linux / linux_kernel | 2.6.39-rc3 | 2.6.39-rc3.x |
linux / linux_kernel | - | 2.6.39.3.x |
linux / linux_kernel | 2.6.39 | 2.6.39.x |
linux / linux_kernel | 2.6.39-rc2 | 2.6.39-rc2.x |
linux / linux_kernel | 2.6.39.2 | 2.6.39.2.x |
linux / linux_kernel | 2.6.39-rc5 | 2.6.39-rc5.x |