OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/01/17/11 | patch mailing list exploit third party advisory |
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-0055 | third party advisory issue tracking |
https://access.redhat.com/security/cve/cve-2012-0055 | third party advisory |
http://www.ubuntu.com/usn/USN-1363-1 | third party advisory |
http://www.ubuntu.com/usn/USN-1364-1 | third party advisory |
http://www.ubuntu.com/usn/USN-1384-1 | third party advisory |
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/915941 | third party advisory exploit |