Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.33-rc4-2.6.36
Unaffected system:
Linux kernel 2.6.37rc
Linux kernel 2.6.36.2 (stable)
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45408
Cve id: CVE-2010-4347
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel access permission settings vulnerability. Attackers can exploit this vulnerability to execute arbitrary code at the Kernel level and completely control the affected computers, resulting in DOS.
This vulnerability occurs because debugfs custom_method is open to non-root users.
<* Source: Dave Jones (davej@RedHat.com)
Link: ACPI: debugfs custom_method open to non-root
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/