漏洞信息详情
Linux Kernel GFS2文件属性缺少所有权检查漏洞
漏洞简介
Linux Kernel是开源操作系统Linux所使用的内核。
Linux kernel的源文件fs/gfs2/file.c的do_gfs2_set_flags函数没有正确验证文件的所属关系,本地用户可以借助SETFLAGS ioctl请求绕过特定的访问限制。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
http://www.linux-archive.org/cluster-development/375481-gfs2-fix-permissions-checking-setflags-ioctl-print.html
参考网址
来源: www.kernel.org
链接:http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/incr/patch-2.6.34-git9-git10.bz2
来源: MLIST
名称: [cluster-devel] 20100525 [PATCH 3/3] GFS2: Fix permissions checking for setflags ioctl()
链接:https://www.redhat.com/archives/cluster-devel/2010-May/msg00049.html
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=595579
来源: XF
名称: kernel-gfs2-security-bypass(58926)
链接:http://xforce.iss.net/xforce/xfdb/58926
来源: BID
名称: 40356
链接:http://www.securityfocus.com/bid/40356
来源: MLIST
名称: [oss-security] 20100526 Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership
链接:http://www.openwall.com/lists/oss-security/2010/05/26/1
来源: MLIST
名称: [oss-security] 20100525 Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership
链接:http://www.openwall.com/lists/oss-security/2010/05/25/12
来源: MLIST
名称: [oss-security] 20100525 CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership
链接:http://www.openwall.com/lists/oss-security/2010/05/25/1
来源: git.kernel.org
链接:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7df0e0397b9a18358573274db9fdab991941062f
来源:NSFOCUS 名称:15106 链接:http://www.nsfocus.net/vulndb/15106
受影响实体
- Linux Linux_kernel:2.6.17.1<!--2000-1-1-->
- Linux Linux_kernel:2.6.17.10<!--2000-1-1-->
- Linux Linux_kernel:2.6.17.11<!--2000-1-1-->
- Linux Linux_kernel:2.6.17<!--2000-1-1-->
- Linux Linux_kernel:2.6.16.8<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...