CVE detail
CVE-2012-0056
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
Cloud services provided by Amazon and other companies are being abused by profit-driven cybercriminals to host DDoS bots, Kaspersky Lab reported on Friday.
newswww.securityweek.comJul 28, 2014, 7:02 PM- Week in review: “Frankenmalware”, Kelihos malware author revealed, and the tragic state of SCADA securityHelp Net Security
Here’s an overview of some of last week’s most interesting news: Tool used in Anonymous Megaupload campaign Looking at the LOIC downloads so far this year, it’s clear there has been a sudden, sharp increase in the past few days which coincides with the latest Anonymous campaign. DreamHost hacker accessed pool of unencrypted passwords DreamHost, one of the world’s most popular and well-known web hosting providers, has sent a warning out to its customers saying … More →
newswww.helpnetsecurity.comJan 30, 2012, 12:00 AM - PoC exploits for Linux privilege escalation bug publishedHelp Net Security
The publication of proof-of-concept exploit code for a recently spotted privilege escalation flaw (CVE-2012-0056 ) in the Linux kernel has left Linux vendors scrambling to push out a patch. The flaw affects versions 2.6.39 and above of the Linux kernel code, and the OS’ creator Linus Torvalds published a patch on the official Linux kernel repository more than a week ago. Unfortunately, only RedHat and Ubuntu managed to push out patches for it before PoC … More →
newswww.helpnetsecurity.comJan 26, 2012, 8:31 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-10291CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm Slimbus driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This…
- CVE-2016-10290CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitrary code within the context of the kernel.…
- CVE-2016-10289CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This i…
- CVE-2016-10288CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issu…
- CVE-2016-10287CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This is…
- CVE-2016-10286CVSS 7.0 · High
An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This is…