|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
The Linux Kernel contains a flaw that may allow a local denial of service. The issue is triggered when 'selinux_ptrace' is used to trace a process. The SID that is set while doing so might be replaced later on accessing certain '/proc' files relating to that process, potentially allowing the owner of the original process to enter the other process' domain. This can result in unauthorised access to the target domain, but appears to be more likely to result in a kernel panic and hence in a loss of availability for the platform.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.6.16-rc6 or higher, as it has been reported to fix this vulnerability. For Ubuntu users, the problem can be corrected by upgrading the affected package to version 2.6.10-34.17 (for Ubuntu 5.04) or 2.6.12-10.32 (for Ubuntu 5.10). An upgrade is required as there are no known workarounds.
|
|
Products |
|
Kernel
 |
2.6.6 |
|
|
|
|
|
|
Credit |
- Stephen Smalley - sds
tycho.nsa.gov -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|