The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A327 | vdb entry signature |
http://marc.info/?l=bugtraq&m=105664924024009&w=2 | mailing list |
http://www.redhat.com/support/errata/RHSA-2003-238.html | vendor advisory |
http://www.debian.org/security/2004/dsa-423 | patch vendor advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2003:074 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2003-408.html | vendor advisory |
http://www.debian.org/security/2004/dsa-358 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2003-368.html | patch vendor advisory |