[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 14 Jan 2010 11:38:40 +0800
From: Eugene Teo <eugene@...hat.com>
To: oss-security@...ts.openwall.com
CC: dann frazier <dannf@...nf.org>, fwestphal@...aro.com, kaber@...sh.net,
"Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request: kernel ebtables perm check
On 01/14/2010 08:54 AM, dann frazier wrote:
> Has a CVE been assigned for this issue yet?
Please use CVE-2010-0007. Thanks.
Eugene
> commit dce766af541f6605fa9889892c0280bab31c66ab
> Author: Florian Westphal<fwestphal@...aro.com>
> Date: Fri Jan 8 17:31:24 2010 +0100
>
> netfilter: ebtables: enforce CAP_NET_ADMIN
>
> normal users are currently allowed to set/modify ebtables rules.
> Restrict it to processes with CAP_NET_ADMIN.
>
> Note that this cannot be reproduced with unmodified ebtables
> binary
> because it uses SOCK_RAW.
>
> Signed-off-by: Florian Westphal<fwestphal@...aro.com>
> Cc: stable@...nel.org
> Signed-off-by: Patrick McHardy<kaber@...sh.net>
--
Eugene Teo / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ