Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 14 Jan 2010 11:38:40 +0800
From: Eugene Teo <eugene@...hat.com>
To: oss-security@...ts.openwall.com
CC: dann frazier <dannf@...nf.org>, fwestphal@...aro.com, kaber@...sh.net,
        "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request: kernel ebtables perm check

On 01/14/2010 08:54 AM, dann frazier wrote:
> Has a CVE been assigned for this issue yet?

Please use CVE-2010-0007. Thanks.

Eugene

> commit dce766af541f6605fa9889892c0280bab31c66ab
> Author: Florian Westphal<fwestphal@...aro.com>
> Date:   Fri Jan 8 17:31:24 2010 +0100
>
>      netfilter: ebtables: enforce CAP_NET_ADMIN
>
>      normal users are currently allowed to set/modify ebtables rules.
>      Restrict it to processes with CAP_NET_ADMIN.
>
>      Note that this cannot be reproduced with unmodified ebtables
>      binary
>      because it uses SOCK_RAW.
>
>      Signed-off-by: Florian Westphal<fwestphal@...aro.com>
>      Cc: stable@...nel.org
>      Signed-off-by: Patrick McHardy<kaber@...sh.net>


-- 
Eugene Teo / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ