UDisks Kernel 'mount' Module Loading Security Vulnerability
BID:47680
Info
UDisks Kernel 'mount' Module Loading Security Vulnerability
| Bugtraq ID: | 47680 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-4661 |
| Remote: | No |
| Local: | Yes |
| Published: | May 02 2011 12:00AM |
| Updated: | May 03 2011 04:43PM |
| Credit: | Sebastian Krahmer, SUSE |
| Vulnerable: |
SuSE openSUSE 11.4 SuSE openSUSE 11.3 6tags UDisks 1.0.2 |
| Not Vulnerable: | |
Discussion
UDisks Kernel 'mount' Module Loading Security Vulnerability
UDisks is prone to a security weakness that may allow users to load arbitrary kernel modules.
Successful exploits will allow local users to load arbitrary kernel modules on the affected computer. This may allow attackers to elevate their privileges or perform other attacks.
UDisks is prone to a security weakness that may allow users to load arbitrary kernel modules.
Successful exploits will allow local users to load arbitrary kernel modules on the affected computer. This may allow attackers to elevate their privileges or perform other attacks.
Exploit / POC
UDisks Kernel 'mount' Module Loading Security Vulnerability
Attackers may use readily available network utilities to exploit this issue.
Attackers may use readily available network utilities to exploit this issue.
Solution / Fix
UDisks Kernel 'mount' Module Loading Security Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
UDisks Kernel 'mount' Module Loading Security Vulnerability
References:
References:
- freedesktop Bug #32232: (UDisk)
- UDisk Homepage (6tags)