Heap
10-07-08, 01:10
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2931)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2931)