CVE-2005-2555

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
References
Link Resource
http://secunia.com/advisories/17002 Permissions Required Third Party Advisory
http://secunia.com/advisories/17073 Permissions Required Third Party Advisory
http://secunia.com/advisories/17826 Permissions Required Third Party Advisory
http://secunia.com/advisories/19369 Permissions Required Third Party Advisory
http://secunia.com/advisories/19374 Permissions Required Third Party Advisory
http://www.debian.org/security/2006/dsa-1017
http://www.debian.org/security/2006/dsa-1018 Third Party Advisory
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2
http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 Broken Link
http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
http://www.novell.com/linux/security/advisories/2005_50_kernel.html Broken Link
http://www.redhat.com/support/errata/RHSA-2005-514.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2005-663.html Not Applicable
http://www.securityfocus.com/archive/1/427980/100/0/threaded
http://www.securityfocus.com/bid/14609 Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2005/1878 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444
https://usn.ubuntu.com/169-1/
http://secunia.com/advisories/17002 Permissions Required Third Party Advisory
http://secunia.com/advisories/17073 Permissions Required Third Party Advisory
http://secunia.com/advisories/17826 Permissions Required Third Party Advisory
http://secunia.com/advisories/19369 Permissions Required Third Party Advisory
http://secunia.com/advisories/19374 Permissions Required Third Party Advisory
http://www.debian.org/security/2006/dsa-1017
http://www.debian.org/security/2006/dsa-1018 Third Party Advisory
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2
http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2
http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 Broken Link
http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
http://www.novell.com/linux/security/advisories/2005_50_kernel.html Broken Link
http://www.redhat.com/support/errata/RHSA-2005-514.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2005-663.html Not Applicable
http://www.securityfocus.com/archive/1/427980/100/0/threaded
http://www.securityfocus.com/bid/14609 Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2005/1878 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444
https://usn.ubuntu.com/169-1/
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:386:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_xeon:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc_smp:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://secunia.com/advisories/17002 - Permissions Required, Third Party Advisory () http://secunia.com/advisories/17002 - Permissions Required, Third Party Advisory
References () http://secunia.com/advisories/17073 - Permissions Required, Third Party Advisory () http://secunia.com/advisories/17073 - Permissions Required, Third Party Advisory
References () http://secunia.com/advisories/17826 - Permissions Required, Third Party Advisory () http://secunia.com/advisories/17826 - Permissions Required, Third Party Advisory
References () http://secunia.com/advisories/19369 - Permissions Required, Third Party Advisory () http://secunia.com/advisories/19369 - Permissions Required, Third Party Advisory
References () http://secunia.com/advisories/19374 - Permissions Required, Third Party Advisory () http://secunia.com/advisories/19374 - Permissions Required, Third Party Advisory
References () http://www.debian.org/security/2006/dsa-1017 - () http://www.debian.org/security/2006/dsa-1017 -
References () http://www.debian.org/security/2006/dsa-1018 - Third Party Advisory () http://www.debian.org/security/2006/dsa-1018 - Third Party Advisory
References () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 - () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 -
References () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 - () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 - Broken Link () http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 - Broken Link
References () http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - () http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 -
References () http://www.novell.com/linux/security/advisories/2005_50_kernel.html - Broken Link () http://www.novell.com/linux/security/advisories/2005_50_kernel.html - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2005-514.html - Not Applicable () http://www.redhat.com/support/errata/RHSA-2005-514.html - Not Applicable
References () http://www.redhat.com/support/errata/RHSA-2005-663.html - Not Applicable () http://www.redhat.com/support/errata/RHSA-2005-663.html - Not Applicable
References () http://www.securityfocus.com/archive/1/427980/100/0/threaded - () http://www.securityfocus.com/archive/1/427980/100/0/threaded -
References () http://www.securityfocus.com/bid/14609 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/14609 - Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2005/1878 - Broken Link () http://www.vupen.com/english/advisories/2005/1878 - Broken Link
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10444 -
References () https://usn.ubuntu.com/169-1/ - () https://usn.ubuntu.com/169-1/ -

07 Nov 2023, 01:57

Type Values Removed Values Added
References
  • {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2', 'tags': ['Issue Tracking'], 'refsource': 'CONFIRM'}
  • {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2', 'tags': ['Issue Tracking'], 'refsource': 'CONFIRM'}
  • () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 -
  • () http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=6fc0b4a7a73a81e74d0004732df358f4f9975be2 -

Information

Published : 2005-08-16 04:00

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2555

Mitre link : CVE-2005-2555

CVE.ORG link : CVE-2005-2555


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-264

Permissions, Privileges, and Access Controls