Secunia Logo  
 
CVE Reference: CVE-2008-2148
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2148

Description:
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/42342

UBUNTU
  http://www.ubuntu.com/usn/usn-625-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html

SAID
  Secunia Advisory: SA30241
  Secunia Advisory: SA30198
  Secunia Advisory: SA30818
  Secunia Advisory: SA31107
  Secunia Advisory: SA31628

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0585.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:167

CONFIRM
  http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.3
  http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0169
  http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git;a=commit;h=f9dfda1ad0637a89a64d001cf81478bd8d9b6306

BID
  29134


Return to the previous page.