PT-2009-1110 · Linux · Linux Kernel

Eugene Teo

·

Publicado

2009-12-13

·

Atualizado

2024-06-15

·

CVE-2009-4131

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.32-git6
Description The issue is related to insufficient checks for file permissions in the EXT4 IOC MOVE EXT ioctl implementation in the ext4 filesystem. This allows local users to overwrite arbitrary files via a crafted request. The problem is associated with deficiencies in access control.
Recommendations For Linux kernel versions prior to 2.6.32-git6, update to version 2.6.32-git6 or later to resolve the issue. As a temporary workaround, consider restricting access to the EXT4 IOC MOVE EXT ioctl to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02229
CVE-2009-4131
OPENSUSE-SU-2024:10128-1

Produtos afetados

Linux Kernel