summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2007-4849
blob: 72f463a71cdbf19903cc412ef93e833007315116 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Candidate: CVE-2007-4849
References: 
 http://git.infradead.org/?p=mtd-2.6.git;a=commitdiff;h=9ed437c50d89eabae763dd422579f73fdebf288d
 http://lists.infradead.org/pipermail/linux-mtd-cvs/2007-August/005897.html
 http://dev.laptop.org/ticket/2732
 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9ed437c50d89eabae763dd422579f73fdebf288d
Description: 
 JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux
 systems, when POSIX ACL support is enabled, does not properly store permissions during
 (1) inode creation or (2) ACL setting, which might allow local users to access
 restricted files or directories after a remount of a filesystem, related to "legacy
 modes" and an inconsistency between dentry permissions and inode permissions.
Ubuntu-Description: 
 Permissions were not correctly stored on JFFS2 ACLs.  For systems using
 ACLs on JFFS2, a local attacker may gain access to private files.
Notes: 
 jmm> ACL support was introduced in 2.6.17 with commit aa98d7cf59b5b0764d3502662053489585faf2fe, marking
 jmm> earlier Debian releases as N/A
Bugs: 442245
upstream: released (2.6.23-rc4)
linux-2.6: released (2.6.23-1)
2.6.18-etch-security: released (2.6.18.dfsg.1-13etch3) [bugfix/jffs2-ACL-vs-mode-handling.patch]
2.6.8-sarge-security: N/A
2.4.27-sarge-security: N/A
2.6.15-dapper-security: N/A
2.6.17-edgy-security: N/A
2.6.20-feisty-security: released (2.6.20-16.33)
2.6.22-gutsy-security: released (2.6.22-14.47)

© 2014-2024 Faster IT GmbH | imprint | privacy policy