opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-07-27T01:29:00
Updated: 2024-08-06T23:00:34.168Z
Reserved: 2011-06-15T00:00:00
Link: CVE-2011-2490
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-07-27T02:55:02.087
Modified: 2024-11-21T01:28:23.530
Link: CVE-2011-2490
Redhat
No data.