audit: privilege escalation
| Package(s): | audit | CVE #(s): | CVE-2008-1628 | ||||||||||||||||
| Created: | April 9, 2008 | Updated: | August 1, 2008 | ||||||||||||||||
| Description: | From the Red Hat bugzilla entry: A vulnerability has been reported in Linux Audit, which potentially can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to a boundary error within the "audit_log_user_command()" function in lib/audit_logging.c. This can be exploited to cause a stack-based buffer overflow via an overly long "command" argument and potentially execute arbitrary code with the privileges of the application using libaudit. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
