Linux Kernel connector Security Bypass
SECUNIA ADVISORY ID: SA37113
VERIFY ADVISORY: http://secunia.com/advisories/37113/
DESCRIPTION: A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to bypass certain security restrictions.
The security issue is caused due to unprivileged users being able to send netlink packets to certain subsystems using connector, which can be exploited to e.g. change certain configurations and perform other operations that should not be available to unprivileged users.
SOLUTION: Update to version 2.6.31.5.
PROVIDED AND/OR DISCOVERED BY: Philip Reisner
ORIGINAL ADVISORY: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5
———————————————————————-
