Revision Date: | 2013-12-09 | Version: | 1 | Title: | CVE-2013-4270 on Ubuntu 12.04 LTS (precise) - low. | Description: | The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application. Miroslav Vadkerti discovered a flaw in how the permissions for network sysctls are handled in the Linux kernel. An unprivileged local user could exploit this flaw to have privileged access to files in /proc/sys/net/.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2013-4270
| Platform(s): | Ubuntu 12.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 12.04 LTS (precise) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in precise is not affected.
OR NOT While related to the CVE in some way, the 'linux-armadaxp' package in precise is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-lts-quantal' package in precise is not affected.
OR The 'linux-lts-raring' package in precise was vulnerable but has been fixed (note: '3.8.0-33.48~precise1').
OR NOT While related to the CVE in some way, the 'linux-lts-saucy' package in precise is not affected (note: '3.11.0-13.20~precise2').
OR NOT While related to the CVE in some way, the 'linux-lts-trusty' package in precise is not affected (note: '3.13.0-24.46~precise1').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-ti-omap4' package in precise is not affected.
|
|