CVE
- Id
- 67590
- CVE No.
- CVE-2014-0181
- Status
- Candidate
- Description
- The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
- Phase
- Assigned (20131203)
- Votes
- None (candidate not yet proposed)
- Comments