Bug 146102 - CAN-2005-0504 moxa CAP_SYS_RAWIO missing
Summary: CAN-2005-0504 moxa CAP_SYS_RAWIO missing
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: kernel
Version: 4.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
: ---
Assignee: Dave Jones
QA Contact: Brian Brock
URL:
Whiteboard: impact=moderate,public=20050110
Keywords: Security
Depends On:
Blocks: 144195
TreeView+ depends on / blocked
 
Reported: 2005-01-25 13:07 UTC by Mark J. Cox
Modified: 2015-01-04 22:16 UTC (History)
3 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2005-01-25 19:05:43 UTC


Attachments (Terms of Use)

Description Mark J. Cox 2005-01-25 13:07:08 UTC
The moxa char driver is missing a CAP_SYS_RAWIO check which could allow a local
user the ability to do things like replace the firmware.  This is already fixed
in 2.4-bk and in 2.6.10-ac7 from Alan Cox (although it's ommitted from 2.6.10-ac10).

Patch available:
http://linux.bkbits.net:8080/linux-2.4/cset@41e2c5fb3htiRRycYu5I4skGWXcv5g

There is a rumour that moxa doesn't work with 2.6 at all, so it may not affect
RHEL4, please let us know if this is the case.

Comment 1 Dave Jones 2005-01-25 19:05:43 UTC
config-generic:# CONFIG_MOXA_INTELLIO is not set
config-generic:# CONFIG_MOXA_SMARTIO is not set



Note You need to log in before you can comment on or make changes to this bug.