PT-2009-3738 · Linux · Linux Kernel

Dan Carpenter

·

Published

2009-05-05

·

Updated

2012-03-19

·

CVE-2009-1184

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.27.22 Linux kernel versions 2.6.28.x prior to 2.6.28.10
Description The issue concerns the SELinux subsystem in the Linux kernel. It allows local users to bypass intended restrictions on network traffic due to the selinux ip postroute iptables compat function omitting calls to avc has perm for the node and port when compat net is enabled.
Recommendations For Linux kernel versions prior to 2.6.27.22, update to version 2.6.27.22 or later. For Linux kernel versions 2.6.28.x prior to 2.6.28.10, update to version 2.6.28.10 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1184
DSA-1800-1
DSA-1809-1

Affected Products

Linux Kernel