CVE-2007-4308
CVE-2007-4308
The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.23-rc2http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000005.htmlhttp://lkml.org/lkml/2007/7/23/195http://secunia.com/advisories/26322http://secunia.com/advisories/26643http://secunia.com/advisories/26647http://secunia.com/advisories/26651http://secunia.com/advisories/27212http://secunia.com/advisories/27322