utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-util/oprofile.Upgrade games-sports/racer-bin.Upgrade media-libs/fmod.Upgrade net-libs/webkit-gtk.Upgrade dev-vcs/gitolite.Upgrade net-misc/rsync.Upgrade net-libs/libsoup.Upgrade gnome-base/gdm.Upgrade app-misc/ca-certificates.Upgrade sys-apps/shadow.Upgrade dev-php/PEAR-Mail.Upgrade app-office/gnucash.Upgrade app-admin/syslog-ng.Upgrade net-misc/mrouted.Upgrade x11-apps/xrdb.Upgrade dev-php/PEAR-PEAR.Upgrade net-analyzer/sflowtool.Upgrade media-sound/lastfmplayer.Upgrade dev-libs/xmlsec.Upgrade dev-util/qt-creator.Upgrade sys-fs/lvm2.Upgrade net-misc/vino.Upgrade dev-db/unixODBC.Upgrade media-libs/xine-lib.Upgrade sys-cluster/resource-agents. | Oct 30, 2017 | Jun 9, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 26, 2011 |
| Ubuntu | — | Upgrade oprofile | Nov 8, 2024 | Jun 9, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub