Red Hat Linux User Mode Linux SetUID Installation Vulnerability
BID:6801
Info
Red Hat Linux User Mode Linux SetUID Installation Vulnerability
| Bugtraq ID: | 6801 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0019 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery credited to Johnny Robertson. |
| Vulnerable: |
Redhat Linux 8.0 i386 |
| Not Vulnerable: | |
Discussion
Red Hat Linux User Mode Linux SetUID Installation Vulnerability
It has been reported that under some circumstances, Red Hat Linux may allow unauthorized actions through User-Mode-Linux compatibility. Due to permissions on some components installed with the User-Mode-Linux utilities, a local user could perform actions on the system that require privilege, potentially affecting local host security.
It has been reported that under some circumstances, Red Hat Linux may allow unauthorized actions through User-Mode-Linux compatibility. Due to permissions on some components installed with the User-Mode-Linux utilities, a local user could perform actions on the system that require privilege, potentially affecting local host security.
Exploit / POC
Red Hat Linux User Mode Linux SetUID Installation Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Red Hat Linux User Mode Linux SetUID Installation Vulnerability
Solution:
Fixes that correct this issue have been released:
Redhat Linux 8.0 i386
Solution:
Fixes that correct this issue have been released:
Redhat Linux 8.0 i386
-
Red Hat kernel-utils-2.4-8.28.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/kernel-utils-2.4-8.28.i386.rpm
References
Red Hat Linux User Mode Linux SetUID Installation Vulnerability
References:
References: