[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:021 -- SUSE kernel local privilege escalation

ID: oval:org.secpod.oval:def:400100Date: (C)2012-01-31   (M)2024-02-19
Class: PATCHFamily: unix




The Linux kernel was updated for SUSE Linux Enterprise 11 and openSUSE 11.1 fixing lots of bugs and some security issues. The kernel was also updated to the 2.6.27.21 stable release. CVE-2009-1072: nfsd in the Linux kernel does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option. CVE-2009-0676: The sock_getsockopt function in net/core/sock.c in the Linux kernel does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request. The fix for this was previously incomplete. CVE-2009-0835: The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle a 32-bit process making a 64-bit syscall or a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as stat or chmod. The openSUSE 11.1 kernel was released before the easter weekend already.

Platform:
openSUSE 11.1
Product:
kernel
Reference:
SUSE-SA:2009:021
CVE-2009-0676
CVE-2009-0835
CVE-2009-1072
CVE    3
CVE-2009-0676
CVE-2009-0835
CVE-2009-1072
CPE    1
cpe:/o:opensuse:opensuse:11.1

© SecPod Technologies