Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-2490


opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.


Published

2011-07-27T02:55:02.087

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nrl opie ≤ 2.4.1 Yes
Application nrl opie 2.2 Yes
Application nrl opie 2.3 Yes
Application nrl opie 2.4 Yes
Application nrl opie 2.10 Yes
Application nrl opie 2.11 Yes
Application nrl opie 2.21 Yes
Application nrl opie 2.22 Yes
Application nrl opie 2.32 Yes

References