CVE-2010-0271
published 2010-01-08CVE-2010-0271: hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it…
PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.32%
24.1th percentile
hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r59v-2j67-g78p: hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which
ghsa_unreviewed·2022-05-02
CVE-2010-0271 [MEDIUM] GHSA-r59v-2j67-g78p: hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which
hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.
Red Hat
libspice: Insufficient guest provided memory mappings boundaries validations
vendor_redhat·2010-03-30·CVSS 7.4
CVE-2010-0430 [HIGH] libspice: Insufficient guest provided memory mappings boundaries validations
libspice: Insufficient guest provided memory mappings boundaries validations
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Statement: The CVE-2010-0430 issue was fixed in the kvm packages for Red Hat Enterprise Linux 5 via RHSA-2010:0271, and fixed in the rhev-hypervisor package via RHSA-2010:0476. This CVE was not disclosed at the time the errata were released; therefore, it was not mentioned in them.
No detection rules found.
No public exploits indexed.
http://sunsolve.sun.com/search/document.do?assetkey=1-66-274830-1http://www.securityfocus.com/bid/37656http://www.securitytracker.com/id?1023416http://www.vupen.com/english/advisories/2010/0076https://exchange.xforce.ibmcloud.com/vulnerabilities/55461http://sunsolve.sun.com/search/document.do?assetkey=1-66-274830-1http://www.securityfocus.com/bid/37656http://www.securitytracker.com/id?1023416http://www.vupen.com/english/advisories/2010/0076https://exchange.xforce.ibmcloud.com/vulnerabilities/55461
2010-01-08
Published