UBUNTU-CVE-2015-1350
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.
02 / AFFECTED SOFTWARE
Affected packages
125 explicit affected versions
81 explicit affected versions
17 explicit affected versions
60 explicit affected versions
94 explicit affected versions
92 explicit affected versions
4 explicit affected versions
26 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
11 explicit affected versions
191 explicit affected versions
59 explicit affected versions
103 explicit affected versions
2 explicit affected versions
38 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.
05 / REFERENCES