Linux Kernel PID spoofing permission Elevation Vulnerability
Release date: 2013-09-04
Updated on: 2013-09-06
Affected Systems:
Linux kernel 3.10.x
Description:
--------------------------------------------------------------------------------
Linux Kernel is the Kernel of the Linux operating system.
Linux Kernel 3.10.10 has an error in the implementation of the "scm_check_creds ()" function (net/core/scm. c). Remote attackers can exploit this vulnerability to obtain elevation permissions by deceiving the PID.
<* Source: GIT
Link: http://secunia.com/advisories/54675/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/net/core/scm.c? Id = d661684cf6820331feae71146c35da83d794467e
Linux Kernel: click here
Linux Kernel: click here
Recommended reading:
How to install Linux 3.11 Kernel on Ubuntu
The Ubuntu 13.10 (Saucy Salamander) Kernel has been upgraded to Linux Kernel 3.10 RC5