Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 212141 (CVE-2008-0163)

Summary: Linux Vserver: symlink attack via /proc (CVE-2008-0163)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: kernel, luckyluke, vserver-devs+disabled
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: [linux < 2.6.24.1][gp < 2.6.24-2]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-03-03 01:21:12 UTC
CVE-2008-0163 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0163):
  Linux kernel 2.6, when using vservers, allows local users to access resources
  of other vservers via a symlink attack in /proc.
Comment 1 unnamedrambler 2008-03-21 18:30:59 UTC
[linux < 2.6.24.1]
http://www.securityfocus.com/bid/27704

[gp < 2.6.24-2]
Comment 2 Benedikt Böhm (RETIRED) gentoo-dev 2008-03-21 20:52:21 UTC
no recent version is affected, but not sure which version fixed it
Comment 3 David J Cozatt 2008-05-03 15:16:43 UTC
Safe to assume one of the following is applied and this can be closed? GLSA status?

http://www.securityfocus.com/bid/27704/solution
Comment 4 Benedikt Böhm (RETIRED) gentoo-dev 2010-09-26 08:22:13 UTC
yes, please close.