Busybox CVE-2014-9645
Bug #1420508 reported by
Erica Windisch
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
CirrOS |
Fix Committed
|
Medium
|
Dr. Jens Harbott |
Bug Description
Busybox issued a CVE for a vulnerable modprobe. This is a public vulnerability.
http://
Certain interfaces in the kernel allow unprivileged users to trigger register_module in the kernel, autoloading modules of a specific pattern. With util-linux modprobe, these patterns are usually safe, but with this busybox vulnerability would allow any user to load arbitrary modules known to modprobe.
To post a comment you must log in.
Should be easily fixed by rebuilding with a recent buildroot.