CVE-2011-1006
published 2011-03-22CVE-2011-1006: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.42%
34.5th percentile
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| balbir_singh | libcgroup | <= 0.37 | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| balbir_singh | libcgroup | — | — |
| debian | libcgroup | < libcgroup 0.37.1-1 (bookworm) | libcgroup 0.37.1-1 (bookworm) |
| libcgroup_project | libcgroup | >= 0 < 0.37.1-1 | 0.37.1-1 |
| libcgroup_project | libcgroup | >= 0 < 0.37.1-1 | 0.37.1-1 |
| libcgroup_project | libcgroup | >= 0 < 0.37.1-1 | 0.37.1-1 |
| libcgroup_project | libcgroup | >= 0 < 0.37.1-1 | 0.37.1-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libcgroup: Heap-based buffer overflow by converting list of controllers for given task into an array of strings
vendor_redhat·2011-03-03·CVSS 7.2
CVE-2011-1006 [HIGH] CWE-122 libcgroup: Heap-based buffer overflow by converting list of controllers for given task into an array of strings
libcgroup: Heap-based buffer overflow by converting list of controllers for given task into an array of strings
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
Debian
CVE-2011-1006: libcgroup - Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-comm...
vendor_debian·2011·CVSS 7.2
CVE-2011-1006 [HIGH] CVE-2011-1006: libcgroup - Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-comm...
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
Scope: local
bookworm: resolved (fixed in 0.37.1-1)
bullseye: resolved (fixed in 0.37.1-1)
forky: resolved (fixed in 0.37.1-1)
sid: resolved (fixed in 0.37.1-1)
trixie: resolved (fixed in 0.37.1-1)
GHSA
GHSA-9wjp-w6p5-52xw: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common
ghsa_unreviewed·2022-05-17
CVE-2011-1006 [HIGH] CWE-119 GHSA-9wjp-w6p5-52xw: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
OSV
CVE-2011-1006: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common
osv·2011-03-22·CVSS 7.2
CVE-2011-1006 [HIGH] CVE-2011-1006: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
No detection rules found.
No public exploits indexed.
http://libcg.git.sourceforge.net/git/gitweb.cgi?p=libcg/libcg%3Ba=commit%3Bh=5ae8aea1ecd60c439121d3329d8eaabf13d292c1http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056683.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056734.htmlhttp://lists.opensuse.org/opensuse-updates/2011-04/msg00027.htmlhttp://secunia.com/advisories/43611http://secunia.com/advisories/43758http://secunia.com/advisories/43891http://secunia.com/advisories/44093http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/downloadhttp://www.debian.org/security/2011/dsa-2193http://www.redhat.com/support/errata/RHSA-2011-0320.htmlhttp://www.securityfocus.com/bid/46729http://www.securitytracker.com/id?1025158http://www.vupen.com/english/advisories/2011/0679http://www.vupen.com/english/advisories/2011/0774https://bugzilla.redhat.com/show_bug.cgi?id=678107http://libcg.git.sourceforge.net/git/gitweb.cgi?p=libcg/libcg%3Ba=commit%3Bh=5ae8aea1ecd60c439121d3329d8eaabf13d292c1http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056683.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056734.htmlhttp://lists.opensuse.org/opensuse-updates/2011-04/msg00027.htmlhttp://secunia.com/advisories/43611http://secunia.com/advisories/43758http://secunia.com/advisories/43891http://secunia.com/advisories/44093http://sourceforge.net/projects/libcg/files/libcgroup/v0.37.1/libcgroup-0.37.1.tar.bz2/downloadhttp://www.debian.org/security/2011/dsa-2193http://www.redhat.com/support/errata/RHSA-2011-0320.htmlhttp://www.securityfocus.com/bid/46729http://www.securitytracker.com/id?1025158http://www.vupen.com/english/advisories/2011/0679http://www.vupen.com/english/advisories/2011/0774https://bugzilla.redhat.com/show_bug.cgi?id=678107
2011-03-22
Published