kernel: symlink overflow in the iso9660 filessytem
Package(s): | kernel |
CVE #(s): | CAN-2004-0109
|
Created: | April 14, 2004 |
Updated: | July 15, 2004 |
Description: |
The 2.4 and 2.6 kernels contain a
vulnerability in the iso9660 (CDROM) filesystem which can be used by a
local attacker to obtain root privileges. The exploit requires creating a
specially-crafted filesystem and getting the kernel to mount it. Many
systems are configured to automatically mount CDs on insertion, however, so
the possibility of this vulnerability being exploited by users with
physical access to the system is real. The 2.4.26 kernel contains the fix,
which will also be merged into the upcoming 2.6.6 release. |
Alerts: |
|