imPC@ndo IT

Tracker / CVE-2012-0056

CVE-2012-0056

Medium 6.9

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

Affected products and versions

linux linux_kernel · 2.6.39 → 3.0.18
linux linux_kernel · 3.1 → 3.2.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References