Björn Steinbrink
82fac0542e
[NETFILTER]: Missing check for CAP_NET_ADMIN in iptables compat layer
...
The 32bit compatibility layer has no CAP_NET_ADMIN check in
compat_do_ipt_get_ctl, which for example allows to list the current
iptables rules even without having that capability (the non-compat
version requires it). Other capabilities might be required to exploit
the bug (eg. CAP_NET_RAW to get the nfnetlink socket?), so a plain user
can't exploit it, but a setup actually using the posix capability system
might very well hit such a constellation of granted capabilities.
Signed-off-by: Björn Steinbrink <B.Steinbrink@gmx.de>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2006-10-20 00:21:10 -07:00
..
2006-10-15 23:14:07 -07:00
2006-09-22 14:55:34 -07:00
2006-09-22 14:55:33 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-05-23 15:15:10 -07:00
2006-06-17 21:29:11 -07:00
2006-09-28 18:03:03 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-10-15 23:14:11 -07:00
2006-09-22 15:18:54 -07:00
2006-09-22 15:20:07 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-09-28 18:03:00 -07:00
2006-09-22 15:18:54 -07:00
2006-09-28 18:03:00 -07:00
2006-09-22 15:19:45 -07:00
2006-09-28 18:03:00 -07:00
2006-03-28 17:02:48 -08:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:03 -07:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-03-28 17:02:48 -08:00
2006-09-22 15:20:08 -07:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-01-10 12:54:34 -08:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-09-28 18:03:01 -07:00
2006-10-04 00:30:54 -07:00
2006-03-28 17:02:48 -08:00
2006-09-22 15:19:58 -07:00
2006-10-20 00:21:10 -07:00
2006-09-28 18:01:07 -07:00
2006-09-22 14:55:34 -07:00
2006-09-28 18:03:02 -07:00
2006-09-22 14:55:34 -07:00
2006-10-15 23:14:08 -07:00
2006-09-28 18:03:02 -07:00
2006-03-28 17:02:48 -08:00
2006-09-22 14:55:34 -07:00
2006-09-28 17:54:08 -07:00
2006-09-28 18:03:02 -07:00
2006-09-22 14:55:34 -07:00
2006-09-28 18:03:02 -07:00
2006-09-28 18:00:55 -07:00
2006-10-04 00:30:56 -07:00
2006-09-28 18:03:02 -07:00
2006-09-28 18:03:02 -07:00
2006-03-28 17:02:48 -08:00
2006-10-15 23:14:08 -07:00
2006-03-28 17:02:48 -08:00
2006-09-28 18:03:02 -07:00
2006-09-22 14:55:34 -07:00
2006-09-22 14:55:33 -07:00
2006-10-04 00:30:54 -07:00
2006-09-22 14:55:33 -07:00
2006-10-03 22:34:14 +02:00
2006-09-22 14:55:22 -07:00
2006-06-30 19:25:36 +02:00
2006-09-22 15:18:54 -07:00