First published: Tue May 25 2010(Updated: )
Description of problem: We should be checking for the ownership of the file for which flags are being set, rather than just for write access. Upstream commit: <a href="http://git.kernel.org/linus/7df0e0397b9a18358573274db9fdab991941062f">http://git.kernel.org/linus/7df0e0397b9a18358573274db9fdab991941062f</a> Acknowledgements: Red Hat would like to thank Dan Rosenberg for responsibly reporting this issue. Statement: Red Hat is aware of this issue and is tracking it via the following bug: <a href="https://bugzilla.redhat.com/CVE-2010-1641">https://bugzilla.redhat.com/CVE-2010-1641</a>. This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG as they did not include support for the GFS2 file system. A future kernel update in Red Hat Enterprise Linux 5 will address this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | < |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-595579 is considered medium due to the potential misuse of file ownership checks.
To fix REDHAT-BUG-595579, ensure that your system incorporates the latest patches that address the file ownership check issue.
REDHAT-BUG-595579 affects Red Hat Enterprise Linux 5 and may impact all versions prior to receiving a patch.
The main issue in REDHAT-BUG-595579 is the lack of ownership verification when setting file flags, potentially allowing unauthorized access.
More information about REDHAT-BUG-595579 can be found in the Red Hat Bugzilla database under the corresponding bug ID.