SB2005101901 - Security restrictions bypass in Linux kernel
Published: October 19, 2005 Updated: August 2, 2024
Security Bulletin ID
SB2005101901
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2005-3257)
The vulnerability allows a local user to read and manipulate data.
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.
Remediation
Install update from vendor's website.
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334113
- http://rhn.redhat.com/errata/RHBA-2007-0304.html
- http://secunia.com/advisories/17226
- http://secunia.com/advisories/17826
- http://secunia.com/advisories/17995
- http://secunia.com/advisories/18203
- http://secunia.com/advisories/19185
- http://secunia.com/advisories/19369
- http://secunia.com/advisories/19374
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1018
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:235
- http://www.securityfocus.com/bid/15122
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10615
- https://usn.ubuntu.com/231-1/