Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1641

Опубликовано: 24 мая 2010
Источник: redhat
CVSS2: 2.1

Описание

The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.

Отчет

Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/CVE-2010-1641. This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG as they did not include support for the GFS2 file system. A future kernel update in Red Hat Enterprise Linux 5 will address this issue.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=595579kernel: GFS2: The setflags ioctl() doesn't check file ownership

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.

nvd
около 15 лет назад

The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.

debian
около 15 лет назад

The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel b ...

github
около 3 лет назад

The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.

oracle-oval
почти 15 лет назад

ELSA-2010-0504: kernel security and bug fix update (IMPORTANT)

2.1 Low

CVSS2