Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 212141 (CVE-2008-0163) - Linux Vserver: symlink attack via /proc (CVE-2008-0163)
Summary: Linux Vserver: symlink attack via /proc (CVE-2008-0163)
Status: RESOLVED FIXED
Alias: CVE-2008-0163
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: [linux < 2.6.24.1][gp < 2.6.24-2]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-03-03 01:21 UTC by Robert Buchholz (RETIRED)
Modified: 2013-09-15 19:53 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-03-03 01:21:12 UTC
CVE-2008-0163 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0163):
  Linux kernel 2.6, when using vservers, allows local users to access resources
  of other vservers via a symlink attack in /proc.
Comment 1 unnamedrambler 2008-03-21 18:30:59 UTC
[linux < 2.6.24.1]
http://www.securityfocus.com/bid/27704

[gp < 2.6.24-2]
Comment 2 Benedikt Böhm (RETIRED) gentoo-dev 2008-03-21 20:52:21 UTC
no recent version is affected, but not sure which version fixed it
Comment 3 David J Cozatt 2008-05-03 15:16:43 UTC
Safe to assume one of the following is applied and this can be closed? GLSA status?

http://www.securityfocus.com/bid/27704/solution
Comment 4 Benedikt Böhm (RETIRED) gentoo-dev 2010-09-26 08:22:13 UTC
yes, please close.