PT-2014-6222 · Linux+5 · Linux Kernel+5

Published

2014-07-16

·

Updated

2024-01-19

·

CVE-2014-4943

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.15.7
Description The issue allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. This is related to the PPPoL2TP feature in net/l2tp/l2tp ppp.c.
Recommendations For Linux kernel versions prior to 3.15.7, update to version 3.15.7 or later to resolve the issue.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1969
ALT-PU-2015-1794
CESA-2014_0923
CESA-2014_0924
CVE-2014-4943
DLA-103-1
DSA-2992-1
OPENSUSE-SU-2014_1669-1
OPENSUSE-SU-2014_1677-1
RHSA-2014:0923
RHSA-2014:0924
RHSA-2014:0925
RHSA-2014:1025
RHSA-2014_0923
RHSA-2014_0924
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2281-1
USN-2282-1
USN-2283-1
USN-2284-1
USN-2285-1
USN-2286-1
USN-2287-1
USN-2288-1
USN-2289-1
USN-2290-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu