CVE-2011-2495
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.
- Affected products
- Linux Kernel, Red Hat, Suse Linux Enterprise, Btrfs-Kmp-Pae, Btrfs-Kmp-Xen, Kernel-Desktop-Devel
- Linux Linux Kernel
- ≤ 2.6.39.3, 2.6.39, 2.6.39.1, 2.6.39.2
- CVSS 2.0
- 2.1 LOW
- EPSS
- 0.5% (39th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2012-06-13
CVE-2011-2495 at NVD
No indexed exploits for CVE-2011-2495 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2011-2495 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.