Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49140
CVE (CAN) ID: CVE-2011-2905
Linux Kernel is the Kernel of the Linux operating system.
Linux Kernel has a local permission Escalation Vulnerability in the perf tool. Local attackers can exploit this vulnerability to trick administrators into running perf in directories where malicious configuration files are stored to obtain super user permissions, full control of affected computers.
<* Source: Christian Ohm
Link: http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = aba8d056078e47350d85b06a9cabd5afcc4b72ea
Http://bugs.debian.org/cgi-bin/bugreport.cgi? Bug = 632923
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/