Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4542

Опубликовано: 24 янв. 2013
Источник: redhat
CVSS2: 4.9

Описание

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

Отчет

This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7. Due to the lack of upstream patches and the Moderate impact, we are not planning to address this issue in Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelAffected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux Extended Update Support 5.9kernelAffected
Red Hat Enterprise Linux 6kernelFixedRHSA-2013:049620.02.2013
Red Hat Enterprise Linux 6.2 EUS - Server and Compute Node OnlykernelFixedRHSA-2013:088230.05.2013
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node OnlykernelFixedRHSA-2013:092811.06.2013
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2013:062211.03.2013
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2013:057928.02.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=875360kernel: block: default SCSI command filter does not accomodate commands overlap across device classes

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

nvd
больше 12 лет назад

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

debian
больше 12 лет назад

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly c ...

github
около 3 лет назад

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

oracle-oval
около 12 лет назад

ELSA-2013-2523: Unbreakable Enterprise kernel security and bugfix update (IMPORTANT)

4.9 Medium

CVSS2

Уязвимость CVE-2012-4542