CVE-2014-0470
super - security update
EPSS 0.37%
描述
super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges via unspecified vectors, aka an RLIMIT_NPROC attack.
如何修補 CVE-2014-0470
要修補 CVE-2014-0470,請將受影響套件升級到下列已修補版本。
- Debian/super—升級至 3.30.0-7 或更新版本
- Debian/super—升級至 3.30.0-3+squeeze2 或更新版本
CVE-2014-0470 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 3.30.0-7
- from 0, < 3.30.0-3+squeeze2