Vulnerability CVE-2008-5393


Published: 2008-12-08   Modified: 2012-02-12

Description:
UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

See advisories in our WLB2 database:
Topic
Author
Date
High
Ubuntu Privacy Remix 8.04r1 fixes security issues
Ubuntu
10.12.2008

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Privacy-cd -> Unbuntu privacy remix 

 References:
http://securityreason.com/securityalert/4696
http://www.securityfocus.com/archive/1/498905/100/0/threaded
http://www.securityfocus.com/bid/32629
https://bugs.launchpad.net/bugs/301285
https://exchange.xforce.ibmcloud.com/vulnerabilities/47082

Copyright 2024, cxsecurity.com

 

Back to Top