Sploitus

CVE-2009-1337

3 known exploits for CVE-2009-1337

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

Linux Linux Kernel
≤ 2.6.29, 2.2.27, 2.4.36, 2.4.36.1, 2.4.36.2, 2.4.36.3, 2.4.36.4, 2.4.36.5, 2.4.36.6, 2.6, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.8.1, 2.6.9, 2.6.10, 2.6.11, 2.6.11.1, 2.6.11.2, 2.6.11.3, 2.6.11.4, 2.6.11.5, 2.6.11.6, 2.6.11.7, 2.6.11.8, 2.6.11.9, 2.6.11.10, 2.6.11.11, 2.6.11.12, 2.6.12, 2.6.12.1, 2.6.12.2, 2.6.12.3, 2.6.12.4
CVSS 2.0
4.4 MEDIUM
EPSS
1.3% (67th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2009-04-22
CVE-2009-1337 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2009-1337

Proof-of-concept code and exploit modules indexed by Sploitus