The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-03-12T06:05:00
Updated: 2024-08-06T13:47:41.807Z
Reserved: 2015-01-24T00:00:00
Link: CVE-2014-9645
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-03-12T06:59:00.147
Modified: 2024-11-21T02:21:19.513
Link: CVE-2014-9645
Redhat