CVE-2011-4080 : Detail

CVE-2011-4080

A01-Broken Access Control
0.07%V4
Local
2012-05-24
23h00 +00:00
2012-05-24
23h00 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-264 Category : Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Metrics

An error occured. Please try again later.
Metrics Score Severity CVSS Vector Source
V2 4 AV:L/AC:H/Au:N/C:C/I:N/A:N nvd@nist.gov