uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/11276.php | vdb entry patch vendor advisory |
http://www.kb.cert.org/vuls/id/134025 | third party advisory us government resource |
http://www.ciac.org/ciac/bulletins/n-044.shtml | third party advisory government resource |
http://www.redhat.com/support/errata/RHSA-2003-056.html | patch vendor advisory |
http://www.securityfocus.com/bid/6801 | vdb entry |