Back to search
CVE-2006-2451
Published: Jul 7, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2006:0574
vendor-advisory
x_refsource_REDHAT
SUSE-SR:2006:017
vendor-advisory
x_refsource_SUSE
SUSE-SA:2006:042
vendor-advisory
x_refsource_SUSE
ADV-2006-2699
vdb-entry
x_refsource_VUPEN
20060707 rPSA-2006-0122-1 kernel
mailing-list
x_refsource_BUGTRAQ
20060716 Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
mailing-list
x_refsource_BUGTRAQ
20060714 Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
mailing-list
x_refsource_BUGTRAQ
20060710 Re: rPSA-2006-0122-1 kernel
mailing-list
x_refsource_BUGTRAQ
SUSE-SA:2006:047
vendor-advisory
x_refsource_SUSE
1016451
vdb-entry
x_refsource_SECTRACK
20965
third-party-advisory
x_refsource_SECUNIA
18874
vdb-entry
x_refsource_BID
USN-311-1
vendor-advisory
x_refsource_UBUNTU
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.24
x_refsource_CONFIRM
27030
vdb-entry
x_refsource_OSVDB
21966
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:016
vendor-advisory
x_refsource_SUSE
20953
third-party-advisory
x_refsource_SECUNIA
21498
third-party-advisory
x_refsource_SECUNIA
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=195902
x_refsource_MISC
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.4
x_refsource_CONFIRM
SUSE-SA:2006:049
vendor-advisory
x_refsource_SUSE
20986
third-party-advisory
x_refsource_SECUNIA
20991
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/elmodocs2/security/ASA-2006-162.htm
x_refsource_CONFIRM
20960
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11336
vdb-entry
signature
x_refsource_OVAL
20060712 Linux Kernel 2.6.x PRCTL Core Dump Handling - Local r00t Exploit ( BID 18874 / CVE-2006-2451 )
mailing-list
x_refsource_BUGTRAQ
https://issues.rpath.com/browse/RPL-488
x_refsource_CONFIRM
20060713 Linux sys_prctl LKM based hotfix
mailing-list
x_refsource_BUGTRAQ
21179
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now