CVE-2008-2931 (Kernel) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-2931 (Kernel)


Heap
10-07-08, 01:10
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2931)