vendor:
Unknown
by:
Marco Ivaldi
N/A
CVSS
N/A
Unknown vulnerability in Linux kernel 2.x
Unknown
CWE
Product Name: Unknown
Affected Version From: Linux 2.2.x (on nfs exported files, should be vuln)
Affected Version To: Linux 2.6.x < 2.6.7-rc3 (default configuration)
Patch Exists: NO
Related CWE: CAN-2004-0497
CPE: Unknown
Platforms Tested: Linux
2004
raptor_chown.c – sys_chown missing DAC controls on Linux
Local users can modify the group ID of files, such as NFS exported files in kernel 2.4 (CAN-2004-0497). On Linux 2.6.x < 2.6.7-rc3, it's possible to change the group of files you don't own, even on local filesystems. This may allow a local attacker to perform privilege escalation.
Mitigation:
Unknown