resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, does not properly enforce class-specific exclude rules in some situations, which allows local users to bypass intended access restrictions for USB devices that set their class ID at the interface level.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/15037 | vdb entry patch |
http://www.novell.com/linux/security/advisories/2005_22_sr.html | patch vendor advisory |