Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 139668
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 139475
Assigned To: Gentoo Linux bug wranglers <bug-wranglers@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Kelly Price <bugs@stalag99.net>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 139668 depends on: Show dependency tree
Bug 139668 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-08 07:41 0000
Bump request -- 2.6.17.4 fixes a bug in core dumping that could give a local
user a privlage escalation.

From the changelogs:

commit 4f9619cdd90ac846fa0ca6e9e8a9d87a0d6b4f57
Author: Greg Kroah-Hartman <gregkh@suse.de>
Date:   Thu Jul 6 13:02:28 2006 -0700

    Linux 2.6.17.4

commit 0af184bb9f80edfbb94de46cb52e9592e5a547b0
Author: Greg Kroah-Hartman <gregkh@suse.de>
Date:   Thu Jul 6 13:02:05 2006 -0700

    fix prctl privilege escalation and suid_dumpable (CVE-2006-2451)

    Based on a patch from Ernie Petrides

    During security research, Red Hat discovered a behavioral flaw in core
    dump handling. A local user could create a program that would cause a
    core file to be dumped into a directory they would not normally have
    permissions to write to. This could lead to a denial of service (disk
    consumption), or allow the local user to gain root privileges.

    Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

------- Comment #1 From Jakub Moc (RETIRED) 2006-07-08 07:52:15 0000 -------

*** This bug has been marked as a duplicate of 139475 ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug