CVE-2004-2408 Information

Description

Linux VServer 1.27 and earlier 1.3.9 and earlier and 1.9.1 and earlier shares /proc permissions across all virtual and host servers which allows local users with the ability to set permissions in /proc to obtain system information or cause a denial of service on other virtual servers or the host server.

Reference

http://archives.neohapsis.com/archives/bugtraq/2004-07/0040.html http://linux-vserver.org/ChangeLog http://secunia.com/advisories/12021 http://securitytracker.com/id?1010643 http://www.osvdb.org/7480 http://www.securityfocus.com/bid/10660 https://exchange.xforce.ibmcloud.com/vulnerabilities/16626

Share on: