Описание
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
hardy | released | 2.6.24-27.65 |
intrepid | released | 2.6.27-17.45 |
jaunty | released | 2.6.28-18.59 |
karmic | released | 2.6.31-19.56 |
upstream | released | 2.6.33~rc4 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.6.15-55.82 |
devel | DNE | |
hardy | DNE | |
intrepid | DNE | |
jaunty | DNE | |
karmic | DNE | |
upstream | released | 2.6.33~rc4 |
Показывать по
EPSS
2.1 Low
CVSS2
Связанные уязвимости
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilte ...
net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
ELSA-2010-0147: kernel security and bug fix update (IMPORTANT)
EPSS
2.1 Low
CVSS2