Upstream information
Description
VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.NVD CVSS v2 Base Score: 3.6 (AV:L/AC:L/Au:N/C:N/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 353496 SUSE Security Advisories:- SUSE-SA:2008:006, published Thu, 07 Feb 2008 11:00:00 +0000
- SUSE-SA:2008:013, published Thu, 06 Mar 2008 16:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE LINUX 10.1 |
| |
| openSUSE 10.2 |
| |
| SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T |
| sles10-debuginfo.x86-64 sles10.x86-64 ZYPP Patch Nr: 4938 |
| SUSE Linux Enterprise 10 SP1 DEBUGINFO for AMD64 and Intel EM64T |
| sles10-debuginfo.x86-64 sles10.x86-64 ZYPP Patch Nr: 4938 |
| SLE SDK 10 SP1 for X86-64 |
| sles10-debuginfo.x86-64 sles10.x86-64 ZYPP Patch Nr: 4938 |
| SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T |
| sles10-debuginfo.x86-64 sles10.x86-64 ZYPP Patch Nr: 4938 |
| openSUSE 10.3 |
| |
| openSUSE 10.3 |
| |
| SUSE Linux Enterprise Server RT Solution 10 for x86 |
| Builds |
| SUSE Linux Enterprise Server RT Solution 10 for AMD64 and Intel EM64T |
| Builds |
| SUSE Linux Enterprise 10 SP1 DEBUGINFO for IBM POWER |
| sles10-debuginfo.ppc sles10.ppc ZYPP Patch Nr: 4937 |
| SLE SDK 10 SP1 for IBM iSeries and IBM pSeries |
| sles10-debuginfo.ppc sles10.ppc ZYPP Patch Nr: 4937 |
| SUSE Linux Enterprise Server 10 SP1 for IBM POWER |
| sles10-debuginfo.ppc sles10.ppc ZYPP Patch Nr: 4937 |
| SUSE Linux Enterprise 10 SP1 DEBUGINFO for IBM zSeries 64bit |
| sles10-debuginfo.s390x sles10.s390x ZYPP Patch Nr: 4942 |
| SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit |
| sles10-debuginfo.s390x sles10.s390x ZYPP Patch Nr: 4942 |
| SUSE Linux Enterprise Desktop 10 SP1 for x86 |
| sles10.x86 sles10-debuginfo.x86 ZYPP Patch Nr: 4935 |
| SUSE Linux Enterprise 10 SP1 DEBUGINFO for x86 |
| sles10.x86 sles10-debuginfo.x86 ZYPP Patch Nr: 4935 |
| SLE SDK 10 SP1 for x86 |
| sles10.x86 sles10-debuginfo.x86 ZYPP Patch Nr: 4935 |
| SUSE Linux Enterprise Server 10 SP1 for x86 |
| sles10.x86 sles10-debuginfo.x86 ZYPP Patch Nr: 4935 |
| SUSE Linux Enterprise 10 SP1 DEBUGINFO for IPF |
| sles10-debuginfo.ia64 sles10.ia64 ZYPP Patch Nr: 4936 |
| SLE SDK 10 SP1 for IPF |
| sles10-debuginfo.ia64 sles10.ia64 ZYPP Patch Nr: 4936 |
| SUSE Linux Enterprise Server 10 SP1 for IPF |
| sles10-debuginfo.ia64 sles10.ia64 ZYPP Patch Nr: 4936 |
