PoC Index

CVE-2010-3850

LOW 2.1EPSS 0.8%

The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.

CVSS v2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.80% chance of exploitation in the next 30 days, 54th percentile
Published
2010-12-30
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (2)

References

Related