CVE-2011-2490
Summary
| CVE | CVE-2011-2490 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-27 02:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nrl | Opie | 2.10 | All | All | All |
| Application | Nrl | Opie | 2.11 | All | All | All |
| Application | Nrl | Opie | 2.2 | All | All | All |
| Application | Nrl | Opie | 2.21 | All | All | All |
| Application | Nrl | Opie | 2.22 | All | All | All |
| Application | Nrl | Opie | 2.3 | All | All | All |
| Application | Nrl | Opie | 2.32 | All | All | All |
| Application | Nrl | Opie | 2.4 | All | All | All |
| Application | Nrl | Opie | All | test1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian update for opie - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Hermes - openSUSE Notification Client | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | |
| OPIE "__opiereadrec()" Off-by-One and "opielogin" Privilege Escalation Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - CVE requests: opie off by one and setuid() failure | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit, Patch |
| #631345 - opie: missing setuid() retval check in opielogin - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Patch |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzillafiles.novell.org | Patch |
| Security Advisory SA45448 - SUSE update for opie - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: CVE requests: opie off by one and setuid() failure | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit, Patch |
| Debian -- Security Information -- DSA-2281-1 opie | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Bug 698772 – VUL-0: opie: off by one errors in opiesu | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.novell.com | Exploit, Patch |
| Hermes - openSUSE Notification Client | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | |
| OPIE Off By One Buffer Overflow Vulnerability and Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.