Total vulnerabilities in the database
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | - | 3.14.1.x |
redhat / enterprise_linux_server | 5.0 | 5.0.x |
suse / linux_enterprise_server | 11-sp1 | 11-sp1.x |
opensuse / evergreen | 11.4 | 11.4.x |
suse / linux_enterprise_real_time_extension | 11-sp3 | 11-sp3.x |
redhat / enterprise_linux_desktop | 5 | 5.x |
suse / linux_enterprise_server | 10-sp4 | 10-sp4.x |
suse / suse_linux_enterprise_server | 11 | 11.x |