SB2005101901 - Security restrictions bypass in Linux kernel 



SB2005101901 - Security restrictions bypass in Linux kernel

Published: October 19, 2005 Updated: August 2, 2024

Security Bulletin ID SB2005101901
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2005-3257)

The vulnerability allows a local user to read and manipulate data.

The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.


Remediation

Install update from vendor's website.