CVE-2011-1020: Infoleak
Last updated 24 July 2024
Other sources
The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1020?
CVE-2011-1020 is considered a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2011-1020?
To fix CVE-2011-1020, upgrade to a version of the Linux kernel newer than 2.6.37 that addresses this vulnerability.
What impact can CVE-2011-1020 have on a system?
CVE-2011-1020 can allow local users to gain access to sensitive information or potentially cause a denial of service.
Which versions of the Linux kernel are affected by CVE-2011-1020?
CVE-2011-1020 affects Linux kernel versions up to and including 2.6.37.
Can CVE-2011-1020 be exploited remotely?
CVE-2011-1020 is a local privilege escalation vulnerability and cannot be directly exploited remotely.