libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
BID:46578
Info
libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
| Bugtraq ID: | 46578 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2011-1022 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 18 2011 12:00AM |
| Updated: | Apr 13 2015 09:46PM |
| Credit: | Nelson Elhage |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Pardus Linux 2009 0 libcgroup libcgroup 0 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
libcgroup is prone to a vulnerability that allows attackers to spoof events to the 'cgrulesengd' daemon.
An attacker can exploit this issue to spoof events to the 'cgrulesengd' daemon, which may aid in further attacks.
libcgroup is prone to a vulnerability that allows attackers to spoof events to the 'cgrulesengd' daemon.
An attacker can exploit this issue to spoof events to the 'cgrulesengd' daemon, which may aid in further attacks.
Exploit / POC
libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
Local attackers can exploit this issue with readily available tools.
Local attackers can exploit this issue with readily available tools.
Solution / Fix
libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libcgroup 'cgrulesengd' Daemon Netlink Messages Event Spoofing Vulnerability
References:
References:
- [PATCH 2/2] cgrulesengd: Ignore netlink messages that don't come from the kernel (Nelson Elhage)
- Control Group Configuration (libcgroup)