CVE-2013-1959
LOW 3.7EPSS 1.2%
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
- CVSS v2.0
- 3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P - EPSS
- 1.24% chance of exploitation in the next 30 days, 67th percentile
- Published
- 2013-05-03
- Updated
- 2024-08-06