Candidate: CVE-2005-0839 References: MLIST:[linux-kernel] 20050301 Re: Breakage from patch: Only root should be able to set the N_MOUSE line discipline. URL:http://www.mail-archive.com/linux-kernel@vger.kernel.org/msg64704.html MISC:http://linux.bkbits.net:8080/linux-2.6/cset@41fa6464E1UuGu6zmketEYxm73KSyQ Description: Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions. Notes: dannf> This file isn't in <= 2.4.27 Bugs: 301372 upstream: released (2.6.11) linux-2.6: N/A 2.6.8-sarge-security: released (2.6.8-16) [drivers-input-serio-nmouse.dpatch] 2.4.27-sarge-security: N/A 2.4.19-woody-security: N/A 2.4.18-woody-security: N/A 2.4.17-woody-security: N/A 2.4.16-woody-security: N/A 2.4.17-woody-security-hppa: N/A 2.4.17-woody-security-ia64: N/A 2.4.18-woody-security-hppa: N/A