Linux Kernel Drivers Lets Local Users Gain Root Privileges
|
|
SecurityTracker Alert ID: 1019357
|
|
SecurityTracker URL: http://securitytracker.com/id?1019357
|
|
CVE Reference: CVE-2008-0007
(Links to External Site)
|
Date: Feb 11 2008
|
Impact: Disclosure of system information, Modification of system information, Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 2.6.22.17
|
Description: A vulnerability was reported in Linux Kernel. A local user can obtain root privileges on the target system.
Certain drivers that register a fault handler do not properly validate user-supplied arguments. A local user may be able to read or write to arbitrary kernel memory locations.
|
Impact: A local user can obtain root privileges on the target system.
|
Solution: The vendor has issued a fix (2.6.22.17).
The Linux advisory is available at:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17
|
Vendor URL: www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17 (Links to External Site)
|
Cause: Access control error
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 11 Feb 2008 15:09:17 -0500
Subject: Linux kernel
|
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17
CVE-2008-0007
|
|