imPC@ndo IT

Tracker / CVE-2007-6206

CVE-2007-6206

Low 2.1

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel
linux linux_kernel · 2.4.0 → 2.4.35.2
linux linux_kernel · 2.6.0 → 2.6.24
opensuse opensuse
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_server
redhat enterprise_linux_workstation
suse linux_enterprise_desktop
suse linux_enterprise_real_time_extension
suse linux_enterprise_server
suse linux_enterprise_software_development_kit

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References