{"id":"UBUNTU-CVE-2011-1006","details":"Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.","modified":"2025-07-16T07:16:59.499495Z","published":"2011-03-22T17:55:00Z","withdrawn":"2025-07-18T16:42:41Z","upstream":["CVE-2011-1006"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-1006"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-1006"}],"affected":[{"package":{"name":"libcgroup","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/libcgroup@0.38-1ubuntu2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.38-1ubuntu2"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"cgroup-bin","binary_version":"0.38-1ubuntu2"},{"binary_name":"libcgroup-dev","binary_version":"0.38-1ubuntu2"},{"binary_name":"libcgroup1","binary_version":"0.38-1ubuntu2"},{"binary_name":"libpam-cgroup","binary_version":"0.38-1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1006.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}