Vulnerabilities > CVE-2005-4418 - Unspecified vulnerability in Vserver Util-Vserver 0/0.30.209
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN vserver
nessus
Summary
util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1011.NASL |
description | Several vulnerabilities have been discovered in the Debian vserver support for Linux. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2005-4347 Bjorn Steinbrink discovered that the chroot barrier is not set correctly with util-vserver which may result in unauthorised escapes from a vserver to the host system. This vulnerability is limited to the 2.4 kernel patch included in kernel-patch-vserver. The correction to this problem requires updating the util-vserver package as well and installing a new kernel built from the updated kernel-patch-vserver package. - CVE-2005-4418 The default policy of util-vserver is set to trust all unknown capabilities instead of considering them as insecure. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22553 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22553 |
title | Debian DSA-1011-1 : kernel-patch-vserver - missing attribute support |
code |
|
References
- http://secunia.com/advisories/19333
- http://secunia.com/advisories/19333
- http://secunia.com/advisories/19339
- http://secunia.com/advisories/19339
- http://www.debian.org/security/2006/dsa-1011
- http://www.debian.org/security/2006/dsa-1011
- http://www.securityfocus.com/bid/17180
- http://www.securityfocus.com/bid/17180
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25407