>> Linux Kernel Memory Mapping Protection Local Security Bypass Vulnerability
Title : Linux Kernel Memory Mapping Protection Local Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-1391 CVE ID : CVE-2006-1524 - CVE-2006-2071
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-04-18
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by attackers to bypass security restrictions. This flaw is due to errors in the "ipc/shm.c" and "mm/madvise.c" files that do not properly validate shared memory permissions, which could be exploited by attackers to gain write access to read-only "tmpfs" files or shared memory via a specially crafted "madvise" call.