[linux-source] [CVE-2007-6206] local coredump information disclosure vulnerability

Bug #180294 reported by disabled.user
254
Affects Status Importance Assigned to Milestone
linux-meta (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: linux-source

Quoting CVE-2007-6206:
"The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information."

CVE References

Revision history for this message
Jamie Strandboge (jdstrand) wrote :
Changed in linux-meta:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.