opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2011-07-27T01:29:00

Updated: 2011-09-07T09:00:00

Reserved: 2011-06-15T00:00:00


Link: CVE-2011-2490

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-07-27T02:55:02.087

Modified: 2011-09-07T03:17:30.207


Link: CVE-2011-2490

JSON object: View

cve-icon Redhat Information

No data.

CWE