Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 188644 (CVE-2007-3843)

Summary: Linux Kernel 2.6.x CIFS Signing Options Weakness (CVE-2007-3843)
Product: Gentoo Security Reporter: Matt Fleming (RETIRED) <mjf>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: kernel
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/26366/
Whiteboard: [linux < 2.6.23][genpatches < 2.6.23-1]
Package list:
Runtime testing required: ---

Description Matt Fleming (RETIRED) gentoo-dev 2007-08-12 20:55:45 UTC
A weakness has been reported in the Linux Kernel, which potentially can be exploited by malicious people to bypass certain security restrictions.

The weakness is caused due to the Linux Kernel not correctly enforcing the defined signing options when mounting a CIFS file system. This may weaken the security and can be leveraged to perform further attacks.

The weakness is fixed in version 2.6.23-rc1.