Vulnerability Name: | CVE-2010-2525 (CCN-60241) | ||||||||||||
Assigned: | 2010-07-08 | ||||||||||||
Published: | 2010-07-08 | ||||||||||||
Updated: | 2021-06-28 | ||||||||||||
Summary: | A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-863 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-2525 Source: CCN Type: Linux Kernel GIT Repository GFS2: Fix up system xattrs Source: CCN Type: oss-security Mailing List, Thu, 8 Jul 2010 23:56:21 -0400 Re: kernel: gfs2 acl issue Source: CCN Type: BID-41516 Linux Kernel GFS2 Access Control List (ACL) Security Bypass Vulnerability Source: XF Type: UNKNOWN linux-kernel-gfs2-sec-bypass(60241) Source: MISC Type: Mailing List, Patch, Vendor Advisory https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2646a1f61a3b5525914757f10fa12b5b94713648 Source: MISC Type: Third Party Advisory https://ubuntu.com/security/CVE-2010-2525 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |