CVE-2007-4308 – kernel: Missing ioctl() permission checks in aacraid driver
https://notcve.org/view.php?id=CVE-2007-4308
The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges. Las funciones (1) aac_cfg_open y (2) aac_compat_ioctl en la ruta ioctl de la capa SCSI en el núcleo de Linux anterior a 2.6.23-rc2 no comprueba los permisos para ioctls, lo cual podría permitir a usuarios locales provocar una denegación de servicio u obtener privilegios. • http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.23-rc2 http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html http://lists.vmware.com/pipermail/security-announce/2008/000005.html http://lkml.org/lkml/2007/7/23/195 http://secunia.com/advisories/26322 http://secunia.com/advisories/26643 http://s •