Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/17002 - Permissions Required, Third Party Advisory | |
References | () http://secunia.com/advisories/17073 - Permissions Required, Third Party Advisory | |
References | () http://secunia.com/advisories/17826 - Permissions Required, Third Party Advisory | |
References | () http://secunia.com/advisories/19369 - Permissions Required, Third Party Advisory | |
References | () http://secunia.com/advisories/19374 - Permissions Required, Third Party Advisory | |
References | () http://www.debian.org/security/2006/dsa-1017 - | |
References | () http://www.debian.org/security/2006/dsa-1018 - Third Party Advisory | |
References | () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 - | |
References | () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 - | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 - Broken Link | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - | |
References | () http://www.novell.com/linux/security/advisories/2005_50_kernel.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2005-514.html - Not Applicable | |
References | () http://www.redhat.com/support/errata/RHSA-2005-663.html - Not Applicable | |
References | () http://www.securityfocus.com/archive/1/427980/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/14609 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2005/1878 - Broken Link | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444 - | |
References | () https://usn.ubuntu.com/169-1/ - |
07 Nov 2023, 01:57
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2005-08-16 04:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2555
Mitre link : CVE-2005-2555
CVE.ORG link : CVE-2005-2555
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-264
Permissions, Privileges, and Access Controls