oprofile: command injection/privilege escalation
| Package(s): | oprofile |
CVE #(s): | CVE-2011-1760
|
| Created: | June 6, 2011 |
Updated: | July 26, 2011 |
| Description: |
From the Debian advisory:
OProfile is a performance profiling tool which is configurable by opcontrol, its
control utility. Stephane Chauveau reported several ways to inject arbitrary
commands in the arguments of this utility. If a local unprivileged user is
authorized by sudoers file to run opcontrol as root, this user could use the
flaw to escalate his privileges.
|
| Alerts: |
| Gentoo |
201412-09 |
racer-bin, fmod, PEAR-Mail, lvm2, gnucash, xine-lib, lastfmplayer, webkit-gtk, shadow, PEAR-PEAR, unixODBC, resource-agents, mrouted, rsync, xmlsec, xrdb, vino, oprofile, syslog-ng, sflowtool, gdm, libsoup, ca-certificates, gitolite, qt-creator |
2014-12-11 |
| Fedora |
FEDORA-2011-8087 |
oprofile |
2011-06-10 |
| Fedora |
FEDORA-2011-8076 |
oprofile |
2011-06-10 |
| Debian |
DSA-2254-2 |
oprofile |
2011-07-11 |
| Ubuntu |
USN-1166-1 |
oprofile |
2011-07-11 |
| Debian |
DSA-2254-1 |
oprofile |
2011-06-03 |
|