Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1022
Description:The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.
Test IDs: 1.3.6.1.4.1.25623.1.0.69311   1.3.6.1.4.1.25623.1.0.122230   1.3.6.1.4.1.25623.1.0.69313   1.3.6.1.4.1.25623.1.0.69329   1.3.6.1.4.1.25623.1.0.69715  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1022
1025157
http://www.securitytracker.com/id?1025157
43611
http://secunia.com/advisories/43611
43758
http://secunia.com/advisories/43758
43891
http://secunia.com/advisories/43891
44093
http://secunia.com/advisories/44093
46578
http://www.securityfocus.com/bid/46578
ADV-2011-0679
http://www.vupen.com/english/advisories/2011/0679
ADV-2011-0774
http://www.vupen.com/english/advisories/2011/0774
DSA-2193
http://www.debian.org/security/2011/dsa-2193
FEDORA-2011-2631
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056683.html
FEDORA-2011-2638
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056734.html
RHSA-2011:0320
http://www.redhat.com/support/errata/RHSA-2011-0320.html
[libcg-devel] 20101115 Fwd: libcgroup netlink
http://sourceforge.net/mailarchive/message.php?msg_id=26598749
[libcg-devel] 20110218 [PATCH 2/2] cgrulesengd: Ignore netlink messages that don't come from the kernel.
http://sourceforge.net/mailarchive/message.php?msg_id=27102603
[oss-security] 20110224 CVE request: libcgroup: Failure to verify netlink messages
http://openwall.com/lists/oss-security/2011/02/25/6
[oss-security] 20110225 Re: CVE request: libcgroup: Failure to verify netlink messages
http://openwall.com/lists/oss-security/2011/02/25/11
[oss-security] 20110225 Re: CVE request: libcgroup: Failure to verify netlink messages
http://openwall.com/lists/oss-security/2011/02/25/12
[oss-security] 20110225 Re: CVE request: libcgroup: Failure to verify netlink messages
http://openwall.com/lists/oss-security/2011/02/25/14
[oss-security] 20110225 Re: CVE request: libcgroup: Failure to verify netlink messages
http://openwall.com/lists/oss-security/2011/02/25/9
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615987
http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/download
http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/download
https://bugzilla.redhat.com/show_bug.cgi?id=680409
https://bugzilla.redhat.com/show_bug.cgi?id=680409
openSUSE-SU-2011:0316
http://lists.opensuse.org/opensuse-updates/2011-04/msg00027.html




© 1998-2025 E-Soft Inc. All rights reserved.