Release date: 2011-11-24
Updated on: 2011-11-25
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50809
Cve id: CVE-2011-3632
Linux is the kernel of a free computer.
The Linux Kernel hardlink tool has the local permission escalation vulnerability when merging duplicate files through the complete file system object path name, local attackers can exploit this vulnerability to use the hardlink on directories/files outside the target directory tree through symbolic links to improve their permissions.
<* Source: Jan Lieskovsky (jlieskov@redhat.com)
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 746713
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/