Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
BID:37876
Info
Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
| Bugtraq ID: | 37876 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3556 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 20 2010 12:00AM |
| Updated: | Mar 19 2015 09:22AM |
| Credit: | Bryn M. Reeves |
| Vulnerable: |
VMWare vMA 4.0 RHEL5 VMWare ESX Server 4.0 ESX400-201003405 VMWare ESX Server 4.0 ESX400-200912403 VMWare ESX Server 4.0 ESX400-200909401 VMWare ESX Server 4.0 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE SUSE Linux Enterprise Desktop 10 SP3 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO Red Hat Enterprise Linux EUS 5.4.z server Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Avaya Voice Portal 5.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Communication Manager 5.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
VMWare ESX Server 4.0 ESX400-201005401 |
Discussion
Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
The Red Hat Linux kernel is prone to a security-bypass vulnerability.
Local attackers can exploit this issue to bypass security restrictions and set SCSI host attributes by modifying world-writable files. This may lead to other attacks.
Note that only systems with the 'qla2xxx' driver and NPIV capable hardware are affected.
The Red Hat Linux kernel is prone to a security-bypass vulnerability.
Local attackers can exploit this issue to bypass security restrictions and set SCSI host attributes by modifying world-writable files. This may lead to other attacks.
Note that only systems with the 'qla2xxx' driver and NPIV capable hardware are affected.
Exploit / POC
Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
An attacker can use system tools and utilities to carry out an attack.
An attacker can use system tools and utilities to carry out an attack.
Solution / Fix
Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Red Hat Linux Kernel 'qla2xxx' DriverSecurity Bypass Vulnerability
References:
References: