Candidate: CVE-2005-2555 References: URL:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2555 Description: Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c. Notes: Bugs: upstream: released (2.6.13) linux-2.6: released (2.6.13-1) 2.6.8-sarge-security: released (2.6.8-16sarge2) 2.4.27-sarge-security: released (2.4.27-10sarge2) 2.4.19-woody-security: 2.4.18-woody-security: 2.4.17-woody-security: 2.4.16-woody-security: 2.4.17-woody-security-hppa: 2.4.17-woody-security-ia64: 2.4.18-woody-security-hppa: