Red Hat Security Advisory 2015-0986-01

Discussion in 'News Aggregator' started by Packet Storm, 13 May 2015.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2015-0986-01 - The kexec-tools packages contain the /sbin/kexec binary and utilities that together form the user-space component of the kernel's kexec feature. The /sbin/kexec binary facilitates a new kernel to boot using the kernel's kexec feature either on a normal or a panic reboot. The kexec fastboot mechanism allows booting a Linux kernel from the context of an already running kernel. It was found that the module-setup.sh script provided by kexec-tools created temporary files in an insecure way. A malicious, local user could use this flaw to conduct a symbolic link attack, allowing them to overwrite the contents of arbitrary files.

    Continue reading...
     

Share This Page

Loading...