Security Advisory

CVE-2008-1940

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-04-24 19:00:00
Last updated 2024-08-07 08:41:00
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.