4.6
CVSSv2

CVE-2008-1940

Published: 25/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The RBAC functionality in grsecurity prior to 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.

Vulnerable Product Search on Vulmon Subscribe to Product

grsecurity grsecurity kernel patch 2.6.24.4

grsecurity grsecurity kernel patch 2.4.33

grsecurity grsecurity kernel patch 2.4.33.2

grsecurity grsecurity kernel patch 2.4.33.3

grsecurity grsecurity kernel patch 2.4.33.4

grsecurity grsecurity kernel patch 2.4.34

grsecurity grsecurity kernel patch 2.6.18

Vendor Advisories

Debian Bug report logs - #478133 linux-patch-grsecurity2: CVE-2008-1940 security restriction bypass Package: linux-patch-grsecurity2; Maintainer for linux-patch-grsecurity2 is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for linux-patch-grsecurity2 is src:linux-patch-grsecurity2 (PTS, buildd, popcon) Reported by: Nico G ...