UBUNTU-CVE-2011-2494
Dashboard / Vulnerabilities / UBUNTU-CVE-2011-2494
UBUNTU-CVE-2011-2494
Summary:
Details: kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.
References: https://ubuntu.com/security/CVE-2011-2494, https://lkml.org/lkml/2011/6/24/88, http://www.openwall.com/lists/oss-security/2011/06/24/6, https://ubuntu.com/security/notices/USN-1236-1, https://ubuntu.com/security/notices/USN-1239-1, https://ubuntu.com/security/notices/USN-1242-1, https://ubuntu.com/security/notices/USN-1245-1, https://ubuntu.com/security/notices/USN-1241-1, https://ubuntu.com/security/notices/USN-1243-1, https://ubuntu.com/security/notices/USN-1244-1, https://ubuntu.com/security/notices/USN-1240-1, https://ubuntu.com/security/notices/USN-1253-1, https://ubuntu.com/security/notices/USN-1260-1, https://ubuntu.com/security/notices/USN-1275-1, https://ubuntu.com/security/notices/USN-1279-1, https://ubuntu.com/security/notices/USN-1281-1, https://ubuntu.com/security/notices/USN-1285-1, https://ubuntu.com/security/notices/USN-1294-1, https://www.cve.org/CVERecord?id=CVE-2011-2494
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
