UBUNTU-CVE-2014-0181
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-0181
UBUNTU-CVE-2014-0181
Summary:
Details: The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
References: https://ubuntu.com/security/CVE-2014-0181, http://marc.info/?l=linux-netdev&m=139828154417533&w=2, http://marc.info/?l=linux-netdev&m=139820147526004&w=2, http://marc.info/?l=linux-netdev&m=139820138225967&w=2, http://www.openwall.com/lists/oss-security/2014/04/23/8, https://ubuntu.com/security/notices/USN-2336-1, https://ubuntu.com/security/notices/USN-2337-1, https://www.cve.org/CVERecord?id=CVE-2014-0181
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
