Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-6206
StatusCandidate
DescriptionThe do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
PhaseAssigned (03.12.2007)
SecurityVulns:Linux multiple security vulnerabilities
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6206
ReferencesBID : 26701
 CONFIRM : http://bugzilla.kernel.org/show_bug.cgi?id=3043
 CONFIRM : http://git.kernel.org/?p=linux/kernel/git/torvalds...
 FRSIRT : ADV-2007-4090
 SECUNIA : 27908
 XF : kernel-core-dump-information-disclosure(38841)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru