drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 | vendor advisory broken link |
http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 | vendor advisory |
http://www.kernel.org/hg/linux-2.6/?cmd=changeset%3Bnode=d7067d7d1f92cba14963a430cfbd53098cbbc8fd | |
http://secunia.com/advisories/17280 | third party advisory permissions required |
http://www.securityfocus.com/bid/15154 | vdb entry third party advisory |
http://www.securityfocus.com/advisories/9549 | vdb entry third party advisory vendor advisory |
http://secunia.com/advisories/17114 | third party advisory permissions required |
http://bugs.gentoo.org/show_bug.cgi?id=107893 | patch vendor advisory |