The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/41952 | vdb entry |
http://www.grsecurity.org/news.php#grsec21113 | |
http://secunia.com/advisories/29899 | third party advisory patch vendor advisory |
http://www.securitytracker.com/id?1019919 | vdb entry |
http://www.vupen.com/english/advisories/2008/1323/references | vdb entry |
http://www.securityfocus.com/bid/28889 | vdb entry patch |