>> Linux Kernel "do_coredump" Function Security Bypass and File Manipulation Vulnerability
Title : Linux Kernel "do_coredump" Function Security Bypass and File Manipulation Vulnerability VUPEN ID : VUPEN/ADV-2006-5002 CVE ID : CVE-2006-6304
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-12-14
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by malicious users to bypass security restrictions. This issue is due to an error in the "do_coredump()" [fs/exec.c] function where the "flag" variable is set but never used, which could be exploited by attackers to manipulate certain files.