Secunia Logo
 
CVE Reference: CVE-2008-0001
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0001

Description:
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/39672

UBUNTU
  http://www.ubuntu.com/usn/usn-574-1
  http://www.ubuntu.com/usn/usn-578-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html
  http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html

ST
  1019289

SAID
  Secunia Advisory: SA28806
  Secunia Advisory: SA28706
  Secunia Advisory: SA28748
  Secunia Advisory: SA28626
  Secunia Advisory: SA28664
  Secunia Advisory: SA28628
  Secunia Advisory: SA28485
  Secunia Advisory: SA28558
  Secunia Advisory: SA28971
  Secunia Advisory: SA28643
  Secunia Advisory: SA29245

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0089.html
  http://rhn.redhat.com/errata/RHSA-2008-0055.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:044
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:112

FEDORA

DEBIAN
  http://www.debian.org/security/2008/dsa-1479

CONFIRM
  http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16
  http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021
  http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a
  http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/486485/100/0/threaded

BID
  27280


Return to the previous page.