---
title: "CVE-2011-2490\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-2490?format=md
keywords: index, follow
---

# CVE-2011-2490

Publication date 27 July 2011

Last updated 24 July 2024

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the
return value of the setuid system call, which allows local users to gain
privileges by arranging for an account to already be running its maximum
number of processes.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-2490?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| opie | 11.04 natty | Ignored end of life |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

per mdeslaur, code not compiled

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2490)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-2490)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-2490)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-2490)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-2490>
