>> Linux Kernel "sys_prctl()" Local Privilege Escalation and Denial of Service Vulnerability
Title : Linux Kernel "sys_prctl()" Local Privilege Escalation and Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-2699 CVE ID : CVE-2006-2451
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-07-07
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by local attackers to obtain elevated privileges or cause a denial of service. This flaw is due to an error in the "sys_prctl()" [sys.c] function when dumping core files, which could be exploited by malicious users to consume all available disk space or execute arbitrary commands with "root" privileges.