|
|
Log in / Subscribe / Register

oprofile: command injection/privilege escalation

Package(s):oprofile CVE #(s):CVE-2011-1760
Created:June 6, 2011 Updated:July 26, 2011
Description: From the Debian advisory:

OProfile is a performance profiling tool which is configurable by opcontrol, its control utility. Stephane Chauveau reported several ways to inject arbitrary commands in the arguments of this utility. If a local unprivileged user is authorized by sudoers file to run opcontrol as root, this user could use the flaw to escalate his privileges.

Alerts:
Gentoo 201412-09 racer-bin, fmod, PEAR-Mail, lvm2, gnucash, xine-lib, lastfmplayer, webkit-gtk, shadow, PEAR-PEAR, unixODBC, resource-agents, mrouted, rsync, xmlsec, xrdb, vino, oprofile, syslog-ng, sflowtool, gdm, libsoup, ca-certificates, gitolite, qt-creator 2014-12-11
Fedora FEDORA-2011-8087 oprofile 2011-06-10
Fedora FEDORA-2011-8076 oprofile 2011-06-10
Debian DSA-2254-2 oprofile 2011-07-11
Ubuntu USN-1166-1 oprofile 2011-07-11
Debian DSA-2254-1 oprofile 2011-06-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds