WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.debian.org/security/2013/dsa-2765 | vendor advisory |
http://osvdb.org/97417 | vdb entry |
http://osvdb.org/97416 | vdb entry |
https://security.gentoo.org/glsa/201612-02 | vendor advisory |
http://seclists.org/oss-sec/2013/q3/627 | mailing list patch |
http://savannah.nongnu.org/bugs/?40034 | patch |
http://www.securityfocus.com/bid/62445 | vdb entry |