Back to search
CVE-2009-0675
Published: Feb 22, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
33938
third-party-advisory
x_refsource_SECUNIA
34502
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:0326
vendor-advisory
x_refsource_REDHAT
37471
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:0360
vendor-advisory
x_refsource_REDHAT
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
x_refsource_CONFIRM
DSA-1749
vendor-advisory
x_refsource_DEBIAN
DSA-1794
vendor-advisory
x_refsource_DEBIAN
oval:org.mitre.oval:def:11529
vdb-entry
signature
x_refsource_OVAL
33758
third-party-advisory
x_refsource_SECUNIA
USN-751-1
vendor-advisory
x_refsource_UBUNTU
35011
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20090220 CVE request: kernel: skfp_ioctl inverted logic flaw
mailing-list
x_refsource_MLIST
SUSE-SA:2009:031
vendor-advisory
x_refsource_SUSE
34981
third-party-advisory
x_refsource_SECUNIA
34394
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:8685
vdb-entry
signature
x_refsource_OVAL
DSA-1787
vendor-advisory
x_refsource_DEBIAN
MDVSA-2009:071
vendor-advisory
x_refsource_MANDRIVA
[netdev] 20090128 [PATCH] drivers/net/skfp: if !capable(CAP_NET_ADMIN): inverted logic
mailing-list
x_refsource_MLIST
34680
third-party-advisory
x_refsource_SECUNIA
ADV-2009-3316
vdb-entry
x_refsource_VUPEN
https://bugzilla.redhat.com/show_bug.cgi?id=486534
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6
x_refsource_CONFIRM
35394
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now