Sploitus

CVE-2008-4210

3 known exploits for CVE-2008-4210

fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

Affected products
Linux Kernel, Red Hat
Linux Linux Kernel
≀ 2.6.21.7, 2.2.27, 2.4.36, 2.4.36.1, 2.4.36.2, 2.4.36.3, 2.4.36.4, 2.4.36.5, 2.4.36.6, 2.6, 2.6.18, 2.6.19.4, 2.6.19.5, 2.6.19.6, 2.6.19.7, 2.6.20.16, 2.6.20.17, 2.6.20.18, 2.6.20.19, 2.6.20.20, 2.6.20.21, 2.6.21.5, 2.6.21.6
Fix
Available
CVSS 2.0
4.6 MEDIUM
EPSS
2.1% (81th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2008-09-29
CVE-2008-4210 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2008-4210

Proof-of-concept code and exploit modules indexed by Sploitus