Bug 664082 (CVE-2010-4661)
Summary: | CVE-2010-4661 udisks: arbitrary Linux kernel loading flaw | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | mclasen, security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugs.freedesktop.org/show_bug.cgi?id=32232 | ||
Whiteboard: | |||
Fixed In Version: | udisks 1.0.3 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-06-11 21:04:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 679859 | ||
Bug Blocks: |
Description
Vincent Danen
2010-12-17 23:36:20 UTC
This issue can only be exploited by users who are logged in locally and in an active session. Attempting the same via remote (i.e. via ssh) fails with: Error org.freedesktop.UDisks.Error.PermissionDenied: Not Authorized This has been assigned the name CVE-2010-4661 Created udisks tracking bugs for this issue Affects: fedora-all [bug 679859] Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update to Red Hat Enterprise Linux 6 may address this flaw. This issue did not affect Red Hat Enterprise Linux 4 or 5. Upstream patch: http://cgit.freedesktop.org/udisks/commit/?id=c933a929f07421ec747cebb24d5e620fc2b97037 And fixed in upstream 1.0.3. Current Fedora releases have 1.0.4 so they have been addressed. This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2010-4661 |