| Severity : |
High
|
| Published : |
2012-05-17
|
| Modified : |
2013-02-14
|
| Base Score : |
7.2
|
| Details : |
The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.
|
| Product/Version : |
MVL6 Kernel 2.6.29
|
|
CVE Vulnerabilities List CVE-2012