PT-2006-2089 · Linux+1 · Selinux+1
Stephen Smalley
·
Published
2006-05-05
·
Updated
2018-10-30
·
CVE-2006-1052
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
SELinux for Linux version 2.6.6
Description
The issue concerns the selinux ptrace logic in hooks.c, which allows local users with ptrace permissions to change the tracer SID to an SID of another process.
Recommendations
For SELinux for Linux version 2.6.6, consider restricting ptrace permissions to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Selinux