Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2009-2692 | First vendor Publication | 2009-08-14 |
| Vendor | Cve | Last vendor Modification | 2012-10-22 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 7.2 | Attack Range | Local |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 3.9 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Security Protection
| Impacts | Provides administrator access : Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service. |
Detail
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2692 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:8657 | |||
| Oval ID: | oval:org.mitre.oval:def:8657 | ||
| Title: | VMware kernel NULL pointer dereference vulnerability | ||
| Description: | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-2692 |
Version: | 2 |
| Platform(s): | VMWare ESX Server 4 |
Product(s): | |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:11526 | |||
| Oval ID: | oval:org.mitre.oval:def:11526 | ||
| Title: | Service Console update for COS kernel | ||
| Description: | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-2692 |
Version: | 3 |
| Platform(s): | VMWare ESX Server 3.5 |
Product(s): | |
| Definition Synopsis: | |||
CPE : Common Platform Enumeration
ExploitDB Exploits
| id | Description |
|---|---|
| 2009-08-24 | Linux Kernel 2.4/2.6 sock_sendpage() ring0 Root Exploit (simple ver) |
| 2009-08-18 | Linux Kernel 2.x sock_sendpage() Local Root Exploit (Android Edition) |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 56992 | Linux Kernel Multiple Protocol proto_ops() Initialization NULL Dereference Lo... |
Metasploit Database
| id | Description |
|---|---|
| 2009-08-13 | Linux Kernel Sendpage Local Privilege Escalation |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 23:55:10 |
|
| 2013-05-01 17:22:36 |
|
| 2013-05-01 13:28:04 |
|
| 2013-05-01 09:22:45 |
|
| 2013-05-01 05:38:30 |
|

CVE-2009-2692
(Critical)
(High)








