UBUNTU-CVE-2012-4542
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-4542
Summary:
Details: block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.
References: https://ubuntu.com/security/CVE-2012-4542, https://rhn.redhat.com/errata/RHSA-2013-0496.html, http://marc.info/?l=linux-kernel&m=135903967015813&w=2, https://lkml.org/lkml/2013/1/24/279, https://lkml.org/lkml/2013/5/23/292, https://lkml.org/lkml/2014/8/27/170, https://lore.kernel.org/all/[email protected]/, https://lore.kernel.org/all/[email protected]/, https://www.cve.org/CVERecord?id=CVE-2012-4542
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
