SB2005123113 - Security features in Linux kernel
Published: December 31, 2005
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Security features (CVE-ID: CVE-2005-4351)
CWE-ID: CWE-254 - Security Features
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to read and manipulate data.
The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running.
Remediation
Install update from vendor's website.
References
- http://archives.neohapsis.com/archives/openbsd/2005-10/1523.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041177.html
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-015.txt
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-15.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24037