Upstream information
Description
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.NVD CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 761200 SUSE Security Advisories:- openSUSE-SU-2012:1526-1, published Thu, 22 Nov 2012 11:14:20 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP2 DEBUGINFO |
| sles11-sp2.x86 sles11-sp2.x86-64 SAT Patch Nr: 7106 |
| SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp2.x86 sles11-sp2.x86-64 SAT Patch Nr: 7106 |
| SLE 11 SP2 DEBUGINFO |
| Builds SAT Patch Nr: 6431 |
| SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| Builds SAT Patch Nr: 6431 |
