| 1 |
Candidate:
|
| 2 |
References:
|
| 3 |
BUGTRAQ:20041223 Linux 2.6 Kernel Capability LSM Module Local Privilege Elevation
|
| 4 |
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110384535113035&w=2
|
| 5 |
CONECTIVA:CLA-2005:930
|
| 6 |
URL:http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000930
|
| 7 |
BID:12093
|
| 8 |
URL:http://www.securityfocus.com/bid/12093
|
| 9 |
XF:linux-security-module-gain-privileges(18673)
|
| 10 |
URL:http://xforce.iss.net/xforce/xfdb/18673
|
| 11 |
Description:
|
| 12 |
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not
|
| 13 |
properly handle the credentials of a process that is launched before the
|
| 14 |
module is loaded, which allows local users to gain privileges.
|
| 15 |
Notes:
|
| 16 |
dannf> This code isn't in <= 2.4.27
|
| 17 |
Bugs:
|
| 18 |
upstream: released (2.6.11)
|
| 19 |
linux-2.6: N/A
|
| 20 |
2.6.8-sarge-security: released (2.6.8-14) [025-track_dummy_capability.dpatch, 027-track_dummy_capability.dpatch]
|
| 21 |
2.4.27-sarge-security: N/A
|
| 22 |
2.4.19-woody-security: N/A
|
| 23 |
2.4.18-woody-security: N/A
|
| 24 |
2.4.17-woody-security: N/A
|
| 25 |
2.4.16-woody-security: N/A
|
| 26 |
2.4.17-woody-security-hppa: N/A
|
| 27 |
2.4.17-woody-security-ia64: N/A
|
| 28 |
2.4.18-woody-security-hppa: N/A
|